PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
An attacker must have shell access with system account privileges in order to exploit this vulnerability.
A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
References
Configurations
No configuration.
History
15 Apr 2026, 00:35
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) Los dispositivos PAX Android based POS permiten la escalada de privilegios a través de scripts configurados incorrectamente. Un atacante debe tener acceso al shell con privilegios de cuenta del sistema para poder explotar esta vulnerabilidad. Se incluyó un parche que soluciona este problema en la versión de firmware PayDroid_8.1.0_Sagittarius_V11.1.61_20240226. |
15 Oct 2024, 12:58
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
11 Oct 2024, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-11 13:15
Updated : 2026-04-15 00:35
NVD link : CVE-2023-42133
Mitre link : CVE-2023-42133
CVE.ORG link : CVE-2023-42133
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions
