High severity7.6NVD Advisory· Published Jan 15, 2024· Updated Jun 17, 2026
CVE-2023-4818
CVE-2023-4818
Description
PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.
The attacker must have physical USB access to the device in order to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0
- cpe:2.3:o:paxtechnology:paydroid:7.1.2_aquarius_11.1.50_20230614:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- blog.stmcyber.com/pax-pos-cves-2023/nvdExploitThird Party Advisory
- cert.pl/en/posts/2024/01/CVE-2023-4818/nvdThird Party Advisory
- cert.pl/posts/2024/01/CVE-2023-4818/nvdThird Party Advisory
- ppn.paxengine.com/release/developmentnvdPermissions Required
News mentions
0No linked articles in our index yet.