Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-27198: PAX-Paydroid-Advisories/advisories/2023/CVEs/CVE-2023-27198.md at master · wr3nchsr/PAX-Paydroid-Advisories

PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a specific word in the command to be executed. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE
#vulnerability

Command Execution Through ADB Daemon

PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a specific word in the command to be executed. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE ID

CVE-2023-27198

Vendor

PAX Technology

Product

PAX A930

Version

PayDroid_7.1.1_Virgo_V04.5.02_20220722

CVSS Score

4.3 (AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Category

CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda