← Zuruck zu CVEs
CVE-2023-42134
MEDIUM6.8
Beschreibung
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.
CVE Details
CVSS v3.1 Bewertung6.8
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorPHYSICAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/15/2024
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
paxtechnology:a50paxtechnology:a920_propaxtechnology:paydroid
Schwachen (CWE)
CWE-912
Referenzen
https://blog.stmcyber.com/pax-pos-cves-2023/(cvd@cert.pl)
https://cert.pl/en/posts/2024/01/CVE-2023-4818/(cvd@cert.pl)
https://cert.pl/posts/2024/01/CVE-2023-4818/(cvd@cert.pl)
https://ppn.paxengine.com/release/development(cvd@cert.pl)
https://blog.stmcyber.com/pax-pos-cves-2023/(af854a3a-2127-422b-91ae-364da2661108)
https://cert.pl/en/posts/2024/01/CVE-2023-4818/(af854a3a-2127-422b-91ae-364da2661108)
https://cert.pl/posts/2024/01/CVE-2023-4818/(af854a3a-2127-422b-91ae-364da2661108)
https://ppn.paxengine.com/release/development(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.