{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-11T23:50:03.874","vulnerabilities":[{"cve":{"id":"CVE-2020-36128","sourceIdentifier":"cve@mitre.org","published":"2021-05-07T11:15:08.173","lastModified":"2024-11-21T05:28:46.280","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation."},{"lang":"es","value":"Pax Technology PAXSTORE versiones v7.0.8_20200511171508 y anteriores, está afectada por una vulnerabilidad de suplantación de token.&#xa0;Cada terminal de pago contiene un token de sesión (llamado X-Terminal-Token) para acceder al mercado.&#xa0;Esto permite a la tienda identificar el terminal y poner a disposición las aplicaciones distribuidas por su revendedor.&#xa0;Al interceptar el tráfico HTTPS de la tienda de aplicaciones, es posible recopilar la petición responsable de asignar el X-Terminal-Token al terminal, lo que hace posible crear un X-Terminal-Token pretendiendo ser otro dispositivo.&#xa0;Un atacante puede utilizar este comportamiento para autenticar su propio terminal de pago en la tienda de aplicaciones mediante la suplantación de token"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:paxtechnology:paxstore:*:*:*:*:*:*:*:*","versionEndIncluding":"7.0.8_20200511171508","matchCriteriaId":"4189ECCE-FC22-42FF-B4DF-EB4119EE60D8"}]}]}],"references":[{"url":"https://blog.pridesec.com.br/p/4c972078-5f01-419e-8bea-cf31ff2e3670/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://marketing.paxtechnology.com/about-pax","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.whatspos.com/","source":"cve@mitre.org","tags":["Product"]},{"url":"https://blog.pridesec.com.br/p/4c972078-5f01-419e-8bea-cf31ff2e3670/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://marketing.paxtechnology.com/about-pax","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]},{"url":"https://www.whatspos.com/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}