CVE-2023-42135 affects PAX A920Pro and A50 payment terminals running PayDroid_8.1.0_Sagittarius_V11.1.50 or earlier. This vulnerability allows for local code execution through parameter injection, bypassing input validation during the flashing of a specific partition. Exploitation requires physical USB access to the device, but if successful, it can lead to high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.1.0_sagittarius_11.1.50_20230614CPE matchmatch criteria | cpe:2.3:o:paxtechnology:paydroid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.