CVE-2020-36128: High severity paxstore vulnerability
Pax Technology PAXSTORE v7.0.820200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36128?
CVE-2020-36128 has a medium severity rating due to the potential for token spoofing which could allow unauthorized access to specific marketplace applications.
How do I fix CVE-2020-36128?
To remediate CVE-2020-36128, upgrade to a version of Paxstore higher than 7.0.8_20200511171508 where the vulnerability is patched.
What types of devices are affected by CVE-2020-36128?
CVE-2020-36128 affects payment terminals that use Pax Technology's Paxstore application version 7.0.8_20200511171508 and lower.
What is the nature of the vulnerability in CVE-2020-36128?
CVE-2020-36128 is a token spoofing vulnerability which can allow attackers to impersonate legitimate payment terminals.
Can CVE-2020-36128 lead to data theft?
Yes, if exploited, CVE-2020-36128 can potentially allow an attacker to gain unauthorized access to sensitive marketplace data and applications.