CVE-2023-42135
Estado: ModificadaMedia (6.8)—
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition.
The attacker must have physical USB access to the device in order to exploit this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.59%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-74
- CWE-74
Referencias
- https://blog.stmcyber.com/pax-pos-cves-2023/
- https://cert.pl/en/posts/2024/01/CVE-2023-4818/
- https://cert.pl/posts/2024/01/CVE-2023-4818/
- https://ppn.paxengine.com/release/development
- https://blog.stmcyber.com/pax-pos-cves-2023/
- https://cert.pl/en/posts/2024/01/CVE-2023-4818/
- https://cert.pl/posts/2024/01/CVE-2023-4818/
- https://ppn.paxengine.com/release/development
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-42135",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-42135",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-01-16T15:48:04.937541Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "cvd@cert.pl",
"affectedData": [
{
"vendor": "PAX Technology",
"product": "A920 Pro",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "11.1.50_20230614"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "PAX Technology",
"product": "A50",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "11.1.50_20230614"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-01-15T14:15:24.413",
"references": [
{
"url": "https://blog.stmcyber.com/pax-pos-cves-2023/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/en/posts/2024/01/CVE-2023-4818/",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/posts/2024/01/CVE-2023-4818/",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://ppn.paxengine.com/release/development",
"tags": [
"Permissions Required"
],
"source": "cvd@cert.pl"
},
{
"url": "https://blog.stmcyber.com/pax-pos-cves-2023/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert.pl/en/posts/2024/01/CVE-2023-4818/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert.pl/posts/2024/01/CVE-2023-4818/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ppn.paxengine.com/release/development",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"description": [
{
"lang": "en",
"value": "CWE-74"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-74"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. \n\n\n\n\n\nThe attacker must have physical USB access to the device in order to exploit this vulnerability."
},
{
"lang": "es",
"value": "Los dispositivos PAX A920Pro/A50 con PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 o anterior pueden permitir la ejecución de código local mediante inyección de parámetros al omitir la validación de entrada al actualizar una partición específica. El atacante debe tener acceso USB físico al dispositivo para poder aprovechar esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T06:23:32.197",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "970DD715-DA0A-4E3B-A51A-4B04EEC55CC8",
"versionEndIncluding": "8.1.0_sagittarius_11.1.50_20230614"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:paxtechnology:a920_pro:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FF80918D-3453-4F42-A8A0-DA993C398394"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "970DD715-DA0A-4E3B-A51A-4B04EEC55CC8",
"versionEndIncluding": "8.1.0_sagittarius_11.1.50_20230614"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:paxtechnology:a50:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DFCCCD93-0374-4AE1-8986-E0997B53A51C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cvd@cert.pl"
}