PT-2022-17940 · Pax Technology · Paydroid+1

·

CVE-2022-26581

·

Published

2022-12-16

·

Updated

2024-07-03

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PAX A930 device with PayDroid versions 7.1.1 Virgo V04.3.26T1 20210419 through 7.1.1 Virgo V04.4.02 20211201
Description The issue allows an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in the ADB daemon. The attacker must have physical USB access to the device in order to exploit this issue. The ADB daemon in PAX Technology A930 PayDroid allows the execution of the systool utility in production mode, enabling unauthenticated attackers to perform privileged actions.
Recommendations For PAX A930 device with PayDroid version 7.1.1 Virgo V04.3.26T1 20210419, consider restricting physical USB access to the device to minimize the risk of exploitation. For PAX A930 device with PayDroid version 7.1.1 Virgo V04.4.02 20211201, avoid using the ADB daemon in production mode until a fix is available. As a temporary workaround, consider disabling the execution of specific binaries listed in the ADB daemon until a patch is available.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26581

Affected Products

Pax A930
Paydroid