CVE-2020-36128: High severity paxstore vulnerability

Published May 7, 2021
·
Updated

Pax Technology PAXSTORE v7.0.820200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

Affected Software

1 affected component
Paxtechnology Paxstore<=7.0.8_20200511171508

Event History

May 7, 2021
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-36128?

CVE-2020-36128 has a medium severity rating due to the potential for token spoofing which could allow unauthorized access to specific marketplace applications.

2

How do I fix CVE-2020-36128?

To remediate CVE-2020-36128, upgrade to a version of Paxstore higher than 7.0.8_20200511171508 where the vulnerability is patched.

3

What types of devices are affected by CVE-2020-36128?

CVE-2020-36128 affects payment terminals that use Pax Technology's Paxstore application version 7.0.8_20200511171508 and lower.

4

What is the nature of the vulnerability in CVE-2020-36128?

CVE-2020-36128 is a token spoofing vulnerability which can allow attackers to impersonate legitimate payment terminals.

5

Can CVE-2020-36128 lead to data theft?

Yes, if exploited, CVE-2020-36128 can potentially allow an attacker to gain unauthorized access to sensitive marketplace data and applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203