7.8

CVE-2023-42137

Exploit
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks.




The attacker must have shell access to the device in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A50 Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A6650 Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A800 Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A77 Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A920 Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A920 Pro Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ A920 Max Version -
Paxtechnology ≫ Paydroid Version <= 8.1.0_sagittarius_11.1.50_20230614
   Paxtechnology ≫ D190 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvd@cert.pl 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://blog.stmcyber.com/pax-pos-cves-2023/
Third Party Advisory
Exploit
https://cert.pl/en/posts/2024/01/CVE-2023-4818/
Third Party Advisory
https://cert.pl/posts/2024/01/CVE-2023-4818/
Third Party Advisory
https://ppn.paxengine.com/release/development
Permissions Required