7.8

CVE-2023-42137

Exploit
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks.




The attacker must have shell access to the device in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA50 Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA6650 Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA800 Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA77 Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA920 Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA920 Pro Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyA920 Max Version-
PaxtechnologyPaydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   PaxtechnologyD190 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvd@cert.pl 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.