Lucene search

K
cve[email protected]CVE-2023-42134
HistoryJan 15, 2024 - 2:15 p.m.

CVE-2023-42134

2024-01-1514:15:24
CWE-912
web.nvd.nist.gov
14
cve-2023-42134
pax android
pos devices
paydroid
security vulnerability
local code execution
nvd

6.8 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command.

The attacker must have physical USB access to the device in order to exploit this vulnerability.

Affected configurations

NVD
Node
paxtechnologya920_proMatch-
AND
paxtechnologypaydroidRange8.1.0_sagittarius_v11.1.45_20230314
Node
paxtechnologya50Match-
AND
paxtechnologypaydroidRange8.1.0_sagittarius_v11.1.45_20230314

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Android"
    ],
    "product": "POS terminals",
    "vendor": "PAX Technology",
    "versions": [
      {
        "lessThanOrEqual": "11.1.45_20230314",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

6.8 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%

Related for CVE-2023-42134