CVE-2023-26980
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the home launcher will be loaded before any user applications.
Published:Apr 14, 2023
Last Modified:Nov 21, 2024
EPS:Apr 14, 2023
EPSS Score:0.00013
CVSS Score:7
Affected Products
Vendor
Product
Action
Vendor
Pax
Product
A920 Pro
Pax
A920 Pro
Vendor
Pax
Product
Paydroid
Pax
Paydroid
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
