Parameter Injection Vulnerability in PAX A920Pro and A50 Devices
CVE-2023-42135

6.8MEDIUM

Key Information:

Vendor
CVE Published:
15 January 2024

What is CVE-2023-42135?

PAX A920Pro and A50 devices running PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier are susceptible to a parameter injection flaw that allows local code execution. Attackers with physical USB access can exploit this vulnerability by bypassing input validation when flashing a specific partition. This could potentially lead to unauthorized control and manipulation of the device's functionality, posing a significant risk to the integrity and security of transactions processed on these devices.

Affected Version(s)

A50 0 <= 11.1.50_20230614

A920 Pro 0 <= 11.1.50_20230614

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hubert Jasudowicz, Adam KliĹ› and other members of STM Cyber R&D team
.