Full Report
Privilege escalation vulnerability (CVE-2023-42133) has been found in PAX Android based POS terminals.
Analysis Summary
# Vulnerability: Privilege Escalation in PAX Android POS Terminals
## CVE Details
- CVE ID: CVE-2023-42133
- CVSS Score: N/A (Severity not provided in the source text)
- CWE: CWE-276 (Incorrect Default Permissions)
## Affected Systems
- Products: Android based PAX POS terminals
- Versions: All versions below 11.1.61\_20240226
- Configurations: Requires an attacker to already possess shell access to an account with system privileges.
## Vulnerability Description
The vulnerability is a Privilege Escalation flaw rooted in **Incorrect Default Permissions (CWE-276)** within the software of PAX Android-based POS devices. An attacker who has already gained shell access to a system-level account can exploit this flaw to escalate their privileges further to the **root** account by leveraging improperly configured scripts.
## Exploitation
- Status: Not explicitly stated, but the vulnerability description implies successful exploitation is possible under specific conditions.
- Complexity: Medium (Requires prior system-level shell access)
- Attack Vector: Local (Requires existing system access)
## Impact
- Confidentiality: Unknown (Likely High, given root access)
- Integrity: Unknown (Likely High, given root access)
- Availability: Unknown (Likely High, given root access)
## Remediation
### Patches
- The issue is addressed in firmware version: **PayDroid\_8.1.0\_Sagittarius\_V11.1.61\_20240226** (Implies versions equal to or higher than this build resolve the flaw).
### Workarounds
- No specific workarounds were mentioned in the provided text, other than applying the patch.
## Detection
- **Indicators of compromise:** Not specified.
- **Detection methods and tools:** Not specified. Detection would likely involve auditing configuration files and scripts accessible by non-root system users for improper permission settings or unexpected elevated execution paths.
## References
- Vendor advisories: PAX (via CERT Polska disclosure coordination)
- Relevant links - defanged:
- hxxps://incydent.cert.pl/#!/lang=en
- hxxps://www.cve.org/CVERecord?id=CVE-2023-42133
- hxxps://cert.pl/en/cvd/