← Retour aux CVEs
CVE-2023-42137
HIGH7.8
Description
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie1/15/2024
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
paxtechnology:a50paxtechnology:a6650paxtechnology:a77paxtechnology:a800paxtechnology:a920paxtechnology:a920_maxpaxtechnology:a920_propaxtechnology:d190paxtechnology:paydroid
Faiblesses (CWE)
CWE-59CWE-59
References
https://blog.stmcyber.com/pax-pos-cves-2023/(cvd@cert.pl)
https://cert.pl/en/posts/2024/01/CVE-2023-4818/(cvd@cert.pl)
https://cert.pl/posts/2024/01/CVE-2023-4818/(cvd@cert.pl)
https://ppn.paxengine.com/release/development(cvd@cert.pl)
https://blog.stmcyber.com/pax-pos-cves-2023/(af854a3a-2127-422b-91ae-364da2661108)
https://cert.pl/en/posts/2024/01/CVE-2023-4818/(af854a3a-2127-422b-91ae-364da2661108)
https://cert.pl/posts/2024/01/CVE-2023-4818/(af854a3a-2127-422b-91ae-364da2661108)
https://ppn.paxengine.com/release/development(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.