PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
An attacker must have shell access with system account privileges in order to exploit this vulnerability.
A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Paxtechnology
Paxtechnology paydroid |
|
CPEs | cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:* | |
Vendors & Products |
Paxtechnology
Paxtechnology paydroid |
|
Metrics |
ssvc
|
Fri, 11 Oct 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226. | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-10-11T12:01:13.299Z
Updated: 2024-10-11T14:42:04.239Z
Reserved: 2023-09-07T13:17:57.371Z
Link: CVE-2023-42133
Vulnrichment
Updated: 2024-10-11T14:41:56.881Z
NVD
Status : Awaiting Analysis
Published: 2024-10-11T13:15:15.190
Modified: 2024-10-15T12:58:51.050
Link: CVE-2023-42133
Redhat
No data.