« Volver al listado

CVE-2023-42133

Estado: AplazadaMedia (6.7)—

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.

An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-42133",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-42133",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-11T14:36:06.943195Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cvd@cert.pl",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "cvd@cert.pl",
      "affectedData": [
        {
          "vendor": "PAX",
          "product": "POS terminals",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "11.1.61_20240226",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Android"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:*"
          ],
          "vendor": "paxtechnology",
          "product": "paydroid",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "11.1.61_20240226",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-11T13:15:15.190",
  "references": [
    {
      "url": "https://blog.stmcyber.com/pax-pos-cves-2023/",
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/en/posts/2024/10/CVE-2023-42133",
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/posts/2024/10/CVE-2023-42133",
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://ppn.paxengine.com/release/development?",
      "source": "cvd@cert.pl"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cvd@cert.pl",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.\n\nAn attacker must have shell access with system account privileges in order to exploit this vulnerability.\nA patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226."
    },
    {
      "lang": "es",
      "value": "Los dispositivos PAX Android based POS permiten la escalada de privilegios a través de scripts configurados incorrectamente. Un atacante debe tener acceso al shell con privilegios de cuenta del sistema para poder explotar esta vulnerabilidad. Se incluyó un parche que soluciona este problema en la versión de firmware PayDroid_8.1.0_Sagittarius_V11.1.61_20240226."
    }
  ],
  "lastModified": "2026-06-17T06:23:31.920",
  "sourceIdentifier": "cvd@cert.pl"
}