CVE-2023-42137: High severity paxtechnology a50 vulnerability
PAX Android based POS devices with PayDroid8.1.0SagittariusV11.1.5020230614 or earlier can allow for command execution with high privileges by using malicious symlinks.
The attacker must have shell access to the device in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42137?
CVE-2023-42137 is considered a high severity vulnerability due to its potential for command execution with high privileges.
How does CVE-2023-42137 occur?
CVE-2023-42137 occurs when malicious symlinks are used to exploit PAX Android based POS devices with the specified vulnerable PayDroid version.
Who can exploit CVE-2023-42137?
An attacker must have shell access to the device to exploit CVE-2023-42137.
What devices are affected by CVE-2023-42137?
CVE-2023-42137 affects PAX Android based POS devices running PayDroid version 8.1.0 Sagittarius V11.1.50 released on or before June 14, 2023.
How can I mitigate CVE-2023-42137?
To mitigate CVE-2023-42137, users should upgrade to a later version of PayDroid that addresses this vulnerability.