CVE-2020-28044: High severity pax prolinos vulnerability
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28044?
CVE-2020-28044 is considered a high severity vulnerability due to the potential for unauthorized file access on PAX Point Of Sale devices.
How do I fix CVE-2020-28044?
To mitigate CVE-2020-28044, ensure that physical access to the PAX Point Of Sale device is restricted and consider updating to a patched version of ProlinOS.
What kind of access does CVE-2020-28044 provide to an attacker?
CVE-2020-28044 allows an attacker with physical access to list, read, create, and overwrite files with MAINAPP permissions.
Are all versions of ProlinOS affected by CVE-2020-28044?
Only ProlinOS versions up to and including 2.4.161.8859R are affected by CVE-2020-28044.
What devices are impacted by CVE-2020-28044?
CVE-2020-28044 impacts PAX Point Of Sale devices running the specified versions of ProlinOS.