paxtechnology kayıtları
paxtechnology üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-306 Missing Authentication for Critical Function1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2020-36126İstismar yok | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalationpaxtechnology · paxstore · CWE-639 | Yüksek8,1 | — | %1,4 | 7 May 2021 |
32İzleyin | CVE-2020-36128İstismar yok | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.paxtechnology · paxstore · CWE-290 | Yüksek8,2 | — | %1,2 | 7 May 2021 |
31İzleyin | CVE-2022-26582İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolpaxtechnology · paydroid · CWE-20 | Yüksek7,8 | — | %0,9 | 16 Ara 2022 |
31İzleyin | CVE-2023-42136İstismar yok | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witpaxtechnology · paydroid · CWE-77 | Yüksek7,8 | — | %0,5 | 15 Oca 2024 |
31İzleyin | CVE-2023-42137İstismar yok | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privilepaxtechnology · paydroid · CWE-59 | Yüksek7,8 | — | %0,5 | 15 Oca 2024 |
30İzleyin | CVE-2023-4818İstismar yok | PAX A920 device allows to downgrade bootloader due to a bug in its version check.paxtechnology · paydroid · CWE-74 | Yüksek7,6 | — | %0,7 | 15 Oca 2024 |
28İzleyin | CVE-2022-26580İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries inpaxtechnology · paydroid · CWE-78 | Orta6,8 | — | %1,8 | 16 Ara 2022 |
28İzleyin | CVE-2020-36125İstismar yok | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive opepaxtechnology · paxstore · CWE-306 | Yüksek7,1 | — | %0,9 | 7 May 2021 |
27İzleyin | CVE-2023-42135İstismar yok | PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection paxtechnology · paydroid · CWE-74 | Orta6,8 | — | %0,6 | 15 Oca 2024 |
27İzleyin | CVE-2023-27198İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and inclpaxtechnology · pax a930 firmware · CWE-78 | Orta6,8 | — | %0,6 | 5 Tem 2023 |
27İzleyin | CVE-2023-42134İstismar yok | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subspaxtechnology · paydroid · CWE-912 | Orta6,8 | — | %0,6 | 15 Oca 2024 |
27İzleyin | CVE-2022-26581İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the epaxtechnology · paydroid · CWE-862 | Orta6,8 | — | %0,3 | 16 Ara 2022 |
26İzleyin | CVE-2020-36124İstismar yok | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.paxtechnology · paxstore · CWE-611 | Orta6,5 | — | %1,3 | 7 May 2021 |
26İzleyin | CVE-2020-36127İstismar yok | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.paxtechnology · paxstore · CWE-295 | Orta6,5 | — | %0,7 | 7 May 2021 |
26İzleyin | CVE-2023-42133İstismar yok | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.pax · pos terminals · CWE-276 | Orta6,7 | — | %0,2 | 11 Eki 2024 |
26İzleyin | CVE-2023-27197İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveragingpaxtechnology · pax a930 firmware | Orta6,7 | — | %0,2 | 5 Tem 2023 |
26İzleyin | CVE-2023-27199İstismar yok | PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypapaxtechnology · pax a930 firmware · CWE-290 | Orta6,7 | — | %0,2 | 5 Tem 2023 |
24İzleyin | CVE-2022-26579İstismar yok | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.paxtechnology · paydroid · CWE-345 | Orta6,0 | — | %0,2 | 16 Ara 2022 |
- CVE-2020-3612632İzleyin
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation
YüksekCVSS 8,1İstismar yokEPSS %1paxtechnology · paxstore7 May 2021
- CVE-2020-3612832İzleyin
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability.
YüksekCVSS 8,2İstismar yokEPSS %1paxtechnology · paxstore7 May 2021
- CVE-2022-2658231İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool
YüksekCVSS 7,8İstismar yokEPSS %1paxtechnology · paydroid16 Ara 2022
- CVE-2023-4213631İzleyin
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands wit
YüksekCVSS 7,8İstismar yokEPSS %0paxtechnology · paydroid15 Oca 2024
- CVE-2023-4213731İzleyin
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privile
YüksekCVSS 7,8İstismar yokEPSS %0paxtechnology · paydroid15 Oca 2024
- CVE-2023-481830İzleyin
PAX A920 device allows to downgrade bootloader due to a bug in its version check.
YüksekCVSS 7,6İstismar yokEPSS %1paxtechnology · paydroid15 Oca 2024
- CVE-2022-2658028İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in
OrtaCVSS 6,8İstismar yokEPSS %2paxtechnology · paydroid16 Ara 2022
- CVE-2020-3612528İzleyin
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive ope
YüksekCVSS 7,1İstismar yokEPSS %1paxtechnology · paxstore7 May 2021
- CVE-2023-4213527İzleyin
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection
OrtaCVSS 6,8İstismar yokEPSS %1paxtechnology · paydroid15 Oca 2024
- CVE-2023-2719827İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and incl
OrtaCVSS 6,8İstismar yokEPSS %1paxtechnology · pax a930 firmware5 Tem 2023
- CVE-2023-4213427İzleyin
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subs
OrtaCVSS 6,8İstismar yokEPSS %1paxtechnology · paydroid15 Oca 2024
- CVE-2022-2658127İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the e
OrtaCVSS 6,8İstismar yokEPSS %0paxtechnology · paydroid16 Ara 2022
- CVE-2020-3612426İzleyin
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection.
OrtaCVSS 6,5İstismar yokEPSS %1paxtechnology · paxstore7 May 2021
- CVE-2020-3612726İzleyin
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability.
OrtaCVSS 6,5İstismar yokEPSS %1paxtechnology · paxstore7 May 2021
- CVE-2023-4213326İzleyin
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.
OrtaCVSS 6,7İstismar yokEPSS %0pax · pos terminals11 Eki 2024
- CVE-2023-2719726İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveraging
OrtaCVSS 6,7İstismar yokEPSS %0paxtechnology · pax a930 firmware5 Tem 2023
- CVE-2023-2719926İzleyin
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypa
OrtaCVSS 6,7İstismar yokEPSS %0paxtechnology · pax a930 firmware5 Tem 2023
- CVE-2022-2657924İzleyin
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.
OrtaCVSS 6,0İstismar yokEPSS %0paxtechnology · paydroid16 Ara 2022