CVE-2020-28044
02.11.2020, 21:15
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pax | prolinos | 𝑥 ≤ 2.4.161.8859r |
𝑥
= Vulnerable software versions
Common Weakness Enumeration