CVE-2023-42134

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:paxtechnology:a920_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:paxtechnology:a50:-:*:*:*:*:*:*:*
cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-15 14:15

Updated : 2024-01-19 16:14


NVD link : CVE-2023-42134

Mitre link : CVE-2023-42134

CVE.ORG link : CVE-2023-42134


JSON object : View

Products Affected

paxtechnology

  • a50
  • paydroid
  • a920_pro
CWE
NVD-CWE-Other CWE-912

Hidden Functionality