CVE-2020-10598
Published Apr 1, 2020
Last updated 3 years ago
Overview
- Description
- In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 5.2
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 3.6
- Impact score
- 4.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- ics-cert@hq.dhs.gov
- CWE-693
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:bd:pyxis_medstation_es_firmware:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2FB9A03-78B0-4756-B847-94E2B4FC52CD" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:bd:pyxis_medstation_es:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CFB63AC0-5A51-494D-BDFA-BFD4B66A44D9" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:bd:pyxis_anesthesia_station_es_firmware:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD02216F-7EA2-48DF-8C6A-BC9E27367065" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:bd:pyxis_anesthesia_station_es:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "32F3ACBB-87CA-43D2-8E32-2656BDCFEB8D" } ], "operator": "OR" } ], "operator": "AND" } ]