Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-42133

Description

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.An attacker must have shell access with system account privileges in order to exploit this vulnerability.A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

POC

Reference

- https://blog.stmcyber.com/pax-pos-cves-2023/

Github

No PoCs found on GitHub currently.