CVE-2023-42136: Command Injection
PAX Android based POS devices with PayDroid8.1.0SagittariusV11.1.5020230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word.
The attacker must have shell access to the device in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42136?
CVE-2023-42136 has a critical severity rating as it allows for the execution of arbitrary commands with system account privileges.
How do I fix CVE-2023-42136?
To mitigate CVE-2023-42136, upgrade the PAX Android-based POS devices from PayDroid version 8.1.0_Sagittarius_V11.1.50_20230614 or earlier to a patched version.
What devices are affected by CVE-2023-42136?
CVE-2023-42136 affects PAX devices running the PayDroid operating system version 8.1.0_Sagittarius_V11.1.50_20230614 or earlier.
Who can exploit CVE-2023-42136?
An attacker must have shell access to the PAX device to exploit CVE-2023-42136.
Does CVE-2023-42136 affect all PAX devices?
No, CVE-2023-42136 specifically affects PAX devices running an older version of PayDroid; newer versions should be checked for vulnerability.