CVE-2023-27198: OS Command Injection
PAX A930 device with PayDroid7.1.1VirgoV04.5.0220220722 can allow the execution of arbitrary commands by using the exec service and including a specific word in the command to be executed. The attacker must have physical USB access to the device in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27198?
CVE-2023-27198 is a vulnerability in the PAX A930 device with PayDroid firmware version 7.1.1_Virgo_V04.5.02_20220722 that allows the execution of arbitrary commands by using the exec service and including a specific word in the command.
How can an attacker exploit CVE-2023-27198?
An attacker can exploit CVE-2023-27198 by having physical USB access to the PAX A930 device and using the exec service with a specific word in the command to execute arbitrary commands.
Is the PAX A930 device vulnerable to CVE-2023-27198?
The PAX A930 device with PayDroid firmware version 7.1.1_Virgo_V04.5.02_20220722 is vulnerable to CVE-2023-27198.
How severe is CVE-2023-27198?
CVE-2023-27198 has a severity of medium with a severity value of 6.8.
Is there a fix for CVE-2023-27198?
There is no known fix for CVE-2023-27198 at the moment. It is recommended to update to a secure version of the firmware when available.