paxtechnology records
18 published records for vendor paxtechnology.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-306 Missing Authentication for Critical Function1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2020-36126No exploit | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalationpaxtechnology · paxstore · CWE-639 | High8.1 | — | 1.4% | May 7, 2021 |
32Monitor | CVE-2020-36128No exploit | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.paxtechnology · paxstore · CWE-290 | High8.2 | — | 1.2% | May 7, 2021 |
31Monitor | CVE-2022-26582No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolpaxtechnology · paydroid · CWE-20 | High7.8 | — | 0.9% | Dec 16, 2022 |
31Monitor | CVE-2023-42136No exploit | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witpaxtechnology · paydroid · CWE-77 | High7.8 | — | 0.5% | Jan 15, 2024 |
31Monitor | CVE-2023-42137No exploit | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privilepaxtechnology · paydroid · CWE-59 | High7.8 | — | 0.5% | Jan 15, 2024 |
30Monitor | CVE-2023-4818No exploit | PAX A920 device allows to downgrade bootloader due to a bug in its version check.paxtechnology · paydroid · CWE-74 | High7.6 | — | 0.7% | Jan 15, 2024 |
28Monitor | CVE-2022-26580No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries inpaxtechnology · paydroid · CWE-78 | Medium6.8 | — | 1.8% | Dec 16, 2022 |
28Monitor | CVE-2020-36125No exploit | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive opepaxtechnology · paxstore · CWE-306 | High7.1 | — | 0.9% | May 7, 2021 |
27Monitor | CVE-2023-42135No exploit | PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection paxtechnology · paydroid · CWE-74 | Medium6.8 | — | 0.6% | Jan 15, 2024 |
27Monitor | CVE-2023-27198No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and inclpaxtechnology · pax a930 firmware · CWE-78 | Medium6.8 | — | 0.6% | Jul 5, 2023 |
27Monitor | CVE-2023-42134No exploit | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subspaxtechnology · paydroid · CWE-912 | Medium6.8 | — | 0.6% | Jan 15, 2024 |
27Monitor | CVE-2022-26581No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the epaxtechnology · paydroid · CWE-862 | Medium6.8 | — | 0.3% | Dec 16, 2022 |
26Monitor | CVE-2020-36124No exploit | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.paxtechnology · paxstore · CWE-611 | Medium6.5 | — | 1.3% | May 7, 2021 |
26Monitor | CVE-2020-36127No exploit | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.paxtechnology · paxstore · CWE-295 | Medium6.5 | — | 0.7% | May 7, 2021 |
26Monitor | CVE-2023-42133No exploit | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.pax · pos terminals · CWE-276 | Medium6.7 | — | 0.2% | Oct 11, 2024 |
26Monitor | CVE-2023-27197No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveragingpaxtechnology · pax a930 firmware | Medium6.7 | — | 0.2% | Jul 5, 2023 |
26Monitor | CVE-2023-27199No exploit | PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypapaxtechnology · pax a930 firmware · CWE-290 | Medium6.7 | — | 0.2% | Jul 5, 2023 |
24Monitor | CVE-2022-26579No exploit | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.paxtechnology · paydroid · CWE-345 | Medium6.0 | — | 0.2% | Dec 16, 2022 |
- CVE-2020-3612632Monitor
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation
HighCVSS 8.1No exploitEPSS 1%paxtechnology · paxstoreMay 7, 2021
- CVE-2020-3612832Monitor
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.
HighCVSS 8.2No exploitEPSS 1%paxtechnology · paxstoreMay 7, 2021
- CVE-2022-2658231Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool
HighCVSS 7.8No exploitEPSS 1%paxtechnology · paydroidDec 16, 2022
- CVE-2023-4213631Monitor
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands wit
HighCVSS 7.8No exploitEPSS 0%paxtechnology · paydroidJan 15, 2024
- CVE-2023-4213731Monitor
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privile
HighCVSS 7.8No exploitEPSS 0%paxtechnology · paydroidJan 15, 2024
- CVE-2023-481830Monitor
PAX A920 device allows to downgrade bootloader due to a bug in its version check.
HighCVSS 7.6No exploitEPSS 1%paxtechnology · paydroidJan 15, 2024
- CVE-2022-2658028Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in
MediumCVSS 6.8No exploitEPSS 2%paxtechnology · paydroidDec 16, 2022
- CVE-2020-3612528Monitor
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive ope
HighCVSS 7.1No exploitEPSS 1%paxtechnology · paxstoreMay 7, 2021
- CVE-2023-4213527Monitor
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection
MediumCVSS 6.8No exploitEPSS 1%paxtechnology · paydroidJan 15, 2024
- CVE-2023-2719827Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and incl
MediumCVSS 6.8No exploitEPSS 1%paxtechnology · pax a930 firmwareJul 5, 2023
- CVE-2023-4213427Monitor
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subs
MediumCVSS 6.8No exploitEPSS 1%paxtechnology · paydroidJan 15, 2024
- CVE-2022-2658127Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the e
MediumCVSS 6.8No exploitEPSS 0%paxtechnology · paydroidDec 16, 2022
- CVE-2020-3612426Monitor
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.
MediumCVSS 6.5No exploitEPSS 1%paxtechnology · paxstoreMay 7, 2021
- CVE-2020-3612726Monitor
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.
MediumCVSS 6.5No exploitEPSS 1%paxtechnology · paxstoreMay 7, 2021
- CVE-2023-4213326Monitor
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
MediumCVSS 6.7No exploitEPSS 0%pax · pos terminalsOct 11, 2024
- CVE-2023-2719726Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveraging
MediumCVSS 6.7No exploitEPSS 0%paxtechnology · pax a930 firmwareJul 5, 2023
- CVE-2023-2719926Monitor
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypa
MediumCVSS 6.7No exploitEPSS 0%paxtechnology · pax a930 firmwareJul 5, 2023
- CVE-2022-2657924Monitor
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.
MediumCVSS 6.0No exploitEPSS 0%paxtechnology · paydroidDec 16, 2022