HIGH · 7.8

CVE-2023-42137

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have ...

Vulnerability Description

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PaxtechnologyPaydroid<= 8.1.0_sagittarius_11.1.50_20230614
PaxtechnologyA50-
PaxtechnologyA6650-
PaxtechnologyA800-
PaxtechnologyA77-
PaxtechnologyA920-
PaxtechnologyA920 Pro-
PaxtechnologyA920 Max-
PaxtechnologyD190-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-42137?

CVE-2023-42137 is a vulnerability with a CVSS score of 7.8 (HIGH). PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have ...

How severe is CVE-2023-42137?

CVE-2023-42137 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-42137?

Check the references section above for vendor advisories and patch information. Affected products include: Paxtechnology Paydroid, Paxtechnology A50, Paxtechnology A6650, Paxtechnology A800, Paxtechnology A77.