PT-2022-17940 · Pax Technology · Paydroid+1
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PAX A930 device with PayDroid versions 7.1.1 Virgo V04.3.26T1 20210419 through 7.1.1 Virgo V04.4.02 20211201
Description
The issue allows an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in the ADB daemon. The attacker must have physical USB access to the device in order to exploit this issue. The ADB daemon in PAX Technology A930 PayDroid allows the execution of the systool utility in production mode, enabling unauthenticated attackers to perform privileged actions.
Recommendations
For PAX A930 device with PayDroid version 7.1.1 Virgo V04.3.26T1 20210419, consider restricting physical USB access to the device to minimize the risk of exploitation.
For PAX A930 device with PayDroid version 7.1.1 Virgo V04.4.02 20211201, avoid using the ADB daemon in production mode until a fix is available.
As a temporary workaround, consider disabling the execution of specific binaries listed in the ADB daemon until a patch is available.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pax A930
Paydroid