CVE-2023-4818

HIGH

PAX PayDroid - Bootloader Downgrade via Version Check Bypass

Title source: llm
STIX 2.1

Description

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

References (4)

Core 4
Core References
Permissions Required vendor-advisory
https://ppn.paxengine.com/release/development
Exploit, Third Party Advisory technical-description
https://blog.stmcyber.com/pax-pos-cves-2023/
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2024/01/CVE-2023-4818/
Third Party Advisory third-party-advisory
https://cert.pl/posts/2024/01/CVE-2023-4818/

Scores

CVSS v3 7.6
EPSS 0.0066
EPSS Percentile 47.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (1)
paxtechnology/paydroid 7.1.2_aquarius_11.1.50_20230614
Published Jan 15, 2024
Tracked Since Feb 18, 2026