PT-2024-1563 · Pax · Paydroid

Adam Klis

+1

·

Published

2024-01-15

·

Updated

2024-10-10

·

CVE-2023-42136

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PAX Android based POS devices with PayDroid versions 8.1.0 Sagittarius V11.1.50 20230614 or earlier
Description The issue exists due to insufficient input validation in the PayDroid operating system, allowing an attacker to execute arbitrary commands with system account privilege by shell injection, starting with a specific word. The attacker must have shell access to the device to exploit this issue.
Recommendations For PAX Android based POS devices with PayDroid versions 8.1.0 Sagittarius V11.1.50 20230614 or earlier, consider restricting shell access to the device to minimize the risk of exploitation. As a temporary workaround, limit the use of shell injection to prevent the execution of arbitrary commands until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Special Elements Injection

RCE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01108
CVE-2023-42136

Affected Products

Paydroid