PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: CERT-PL

Published: 2024-01-15T13:28:53.397Z

Updated: 2024-01-15T13:28:53.397Z

Reserved: 2023-09-07T13:17:57.372Z


Link: CVE-2023-42134

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-15T14:15:24.190

Modified: 2024-01-19T16:14:39.460


Link: CVE-2023-42134

JSON object: View

cve-icon Redhat Information

No data.