Записи paxtechnology
18 опубликованных записей вендора paxtechnology.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-306 Missing Authentication for Critical Function1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2020-36126Эксплойта нет | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalationpaxtechnology · paxstore · CWE-639 | Высокая8,1 | — | 1,4 % | 7 мая 2021 г. |
32Наблюдать | CVE-2020-36128Эксплойта нет | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.paxtechnology · paxstore · CWE-290 | Высокая8,2 | — | 1,2 % | 7 мая 2021 г. |
31Наблюдать | CVE-2022-26582Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolpaxtechnology · paydroid · CWE-20 | Высокая7,8 | — | 0,9 % | 16 дек. 2022 г. |
31Наблюдать | CVE-2023-42136Эксплойта нет | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witpaxtechnology · paydroid · CWE-77 | Высокая7,8 | — | 0,5 % | 15 янв. 2024 г. |
31Наблюдать | CVE-2023-42137Эксплойта нет | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privilepaxtechnology · paydroid · CWE-59 | Высокая7,8 | — | 0,5 % | 15 янв. 2024 г. |
30Наблюдать | CVE-2023-4818Эксплойта нет | PAX A920 device allows to downgrade bootloader due to a bug in its version check.paxtechnology · paydroid · CWE-74 | Высокая7,6 | — | 0,7 % | 15 янв. 2024 г. |
28Наблюдать | CVE-2022-26580Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries inpaxtechnology · paydroid · CWE-78 | Средняя6,8 | — | 1,8 % | 16 дек. 2022 г. |
28Наблюдать | CVE-2020-36125Эксплойта нет | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive opepaxtechnology · paxstore · CWE-306 | Высокая7,1 | — | 0,9 % | 7 мая 2021 г. |
27Наблюдать | CVE-2023-42135Эксплойта нет | PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection paxtechnology · paydroid · CWE-74 | Средняя6,8 | — | 0,6 % | 15 янв. 2024 г. |
27Наблюдать | CVE-2023-27198Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and inclpaxtechnology · pax a930 firmware · CWE-78 | Средняя6,8 | — | 0,6 % | 5 июл. 2023 г. |
27Наблюдать | CVE-2023-42134Эксплойта нет | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subspaxtechnology · paydroid · CWE-912 | Средняя6,8 | — | 0,6 % | 15 янв. 2024 г. |
27Наблюдать | CVE-2022-26581Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the epaxtechnology · paydroid · CWE-862 | Средняя6,8 | — | 0,3 % | 16 дек. 2022 г. |
26Наблюдать | CVE-2020-36124Эксплойта нет | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.paxtechnology · paxstore · CWE-611 | Средняя6,5 | — | 1,3 % | 7 мая 2021 г. |
26Наблюдать | CVE-2020-36127Эксплойта нет | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.paxtechnology · paxstore · CWE-295 | Средняя6,5 | — | 0,7 % | 7 мая 2021 г. |
26Наблюдать | CVE-2023-42133Эксплойта нет | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.pax · pos terminals · CWE-276 | Средняя6,7 | — | 0,2 % | 11 окт. 2024 г. |
26Наблюдать | CVE-2023-27197Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveragingpaxtechnology · pax a930 firmware | Средняя6,7 | — | 0,2 % | 5 июл. 2023 г. |
26Наблюдать | CVE-2023-27199Эксплойта нет | PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypapaxtechnology · pax a930 firmware · CWE-290 | Средняя6,7 | — | 0,2 % | 5 июл. 2023 г. |
24Наблюдать | CVE-2022-26579Эксплойта нет | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.paxtechnology · paydroid · CWE-345 | Средняя6,0 | — | 0,2 % | 16 дек. 2022 г. |
- CVE-2020-3612632Наблюдать
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %paxtechnology · paxstore7 мая 2021 г.
- CVE-2020-3612832Наблюдать
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %paxtechnology · paxstore7 мая 2021 г.
- CVE-2022-2658231Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %paxtechnology · paydroid16 дек. 2022 г.
- CVE-2023-4213631Наблюдать
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands wit
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %paxtechnology · paydroid15 янв. 2024 г.
- CVE-2023-4213731Наблюдать
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privile
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %paxtechnology · paydroid15 янв. 2024 г.
- CVE-2023-481830Наблюдать
PAX A920 device allows to downgrade bootloader due to a bug in its version check.
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %paxtechnology · paydroid15 янв. 2024 г.
- CVE-2022-2658028Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in
СредняяCVSS 6,8Эксплойта нетEPSS 2 %paxtechnology · paydroid16 дек. 2022 г.
- CVE-2020-3612528Наблюдать
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive ope
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %paxtechnology · paxstore7 мая 2021 г.
- CVE-2023-4213527Наблюдать
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection
СредняяCVSS 6,8Эксплойта нетEPSS 1 %paxtechnology · paydroid15 янв. 2024 г.
- CVE-2023-2719827Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and incl
СредняяCVSS 6,8Эксплойта нетEPSS 1 %paxtechnology · pax a930 firmware5 июл. 2023 г.
- CVE-2023-4213427Наблюдать
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subs
СредняяCVSS 6,8Эксплойта нетEPSS 1 %paxtechnology · paydroid15 янв. 2024 г.
- CVE-2022-2658127Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the e
СредняяCVSS 6,8Эксплойта нетEPSS 0 %paxtechnology · paydroid16 дек. 2022 г.
- CVE-2020-3612426Наблюдать
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %paxtechnology · paxstore7 мая 2021 г.
- CVE-2020-3612726Наблюдать
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %paxtechnology · paxstore7 мая 2021 г.
- CVE-2023-4213326Наблюдать
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %pax · pos terminals11 окт. 2024 г.
- CVE-2023-2719726Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveraging
СредняяCVSS 6,7Эксплойта нетEPSS 0 %paxtechnology · pax a930 firmware5 июл. 2023 г.
- CVE-2023-2719926Наблюдать
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypa
СредняяCVSS 6,7Эксплойта нетEPSS 0 %paxtechnology · pax a930 firmware5 июл. 2023 г.
- CVE-2022-2657924Наблюдать
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.
СредняяCVSS 6,0Эксплойта нетEPSS 0 %paxtechnology · paydroid16 дек. 2022 г.