Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36128

Опубликовано: 07 мая 2021
Источник: nvd
CVSS3: 8.2
CVSS2: 6.4
EPSS Низкий

Описание

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:paxtechnology:paxstore:*:*:*:*:*:*:*:*
Версия до 7.0.8_20200511171508 (включая)

EPSS

Процентиль: 45%
0.00222
Низкий

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-290

Связанные уязвимости

github
больше 3 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

EPSS

Процентиль: 45%
0.00222
Низкий

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-290