CVE ID | CVE-2023-42133 |
Publication date | 11 October 2024 |
Vendor | PAX |
Product | All Android based PAX POS terminals |
Vulnerable versions | All below 11.1.61_20240226 |
Vulnerability type (CWE) | Incorrect Default Permissions (CWE-276) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in PAX Android-based POS (Point Of Sale) terminals and participated in coordination of its disclosure.
An attacker, who has shell access to an account with system privileges, can exploit CVE-2023-42133 vulnerability in PAX Android based POS devices in order to escalate privileges to root account via improperly configured scripts.
A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
Credits
We thank Hubert Jasudowicz, Adam Kliś and other members of STM Cyber R&D team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.