6.8
CVSSv3

CVE-2020-28044

Published: 02/11/2020 Updated: 17/11/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An attacker with physical access to a PAX Point Of Sale device with ProlinOS up to and including 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pax prolinos