CVE-2023-26980: Race Condition
DISPUTED PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the home launcher will be loaded before any user applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26980?
The severity of CVE-2023-26980 is currently disputed by the vendor, citing that the exploit is not feasible in practical scenarios.
How do I fix CVE-2023-26980?
As of now, there are no specific patches or fixes available for CVE-2023-26980 as the vendor disputes the vulnerability.
What systems are affected by CVE-2023-26980?
CVE-2023-26980 specifically affects the PAX PayDroid 8.1 software running on certain devices such as the PAX A920 Pro.
What kind of attack does CVE-2023-26980 enable?
CVE-2023-26980 allows attackers to potentially bypass payment software and directly boot to Android during the device's boot process.
Why does the vendor dispute CVE-2023-26980?
The vendor disputes CVE-2023-26980's validity by arguing that the necessary conditions for the attack are not feasible.