PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word
Published Jan 15, 2024
7.8
HIGHCVSS 3.1
EPSS 0.48%
Description
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word.
The attacker must have shell access to the device in order to exploit this vulnerability.
Affected products
-
Affected
- ≥ 0, ≤ 11.1.50_20230614
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| PAX Technology | POS terminals | unaffected | Affected
|
Configuration 1
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 2
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 3
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 4
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 5
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 6
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 7
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
Configuration 8
- ≤ 8.1.0_sagittarius_11.1.50_20230614
Running on/with
- n/a
-
Affected
- ≥ 0, ≤ 8.1.0_sagittarius_11.1.50_20230614
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Paxtechnology | Paydroid | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://blog.stmcyber.com/pax-pos-cves-2023/ technical-descriptionExploitThird Party Advisory
- https://cert.pl/en/posts/2024/01/CVE-2023-4818/ third-party-advisoryThird Party Advisory
- https://cert.pl/posts/2024/01/CVE-2023-4818/ third-party-advisoryThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-46595 Advisory
- https://ppn.paxengine.com/release/development vendor-advisoryPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://blog.stmcyber.com/pax-pos-cves-2023/ | technical-descriptionExploitThird Party Advisory | |
| https://cert.pl/en/posts/2024/01/CVE-2023-4818/ | third-party-advisoryThird Party Advisory | |
| https://cert.pl/posts/2024/01/CVE-2023-4818/ | third-party-advisoryThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-46595 | Advisory | |
| https://ppn.paxengine.com/release/development | vendor-advisoryPermissions Required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data