Description
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
An attacker must have shell access with system account privileges in order to exploit this vulnerability.
A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
An attacker must have shell access with system account privileges in order to exploit this vulnerability.
A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46592 | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226. |
References
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paxtechnology
Paxtechnology paydroid |
|
| CPEs | cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paxtechnology
Paxtechnology paydroid |
|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226. | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-10-11T14:42:04.239Z
Reserved: 2023-09-07T13:17:57.371Z
Link: CVE-2023-42133
Updated: 2024-10-11T14:41:56.881Z
Status : Awaiting Analysis
Published: 2024-10-11T13:15:15.190
Modified: 2024-10-15T12:58:51.050
Link: CVE-2023-42133
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD