MEDIUM🇵🇱 Wersja polska

CVE-2020-10598

CVSS 6.1v3.1pub. 2020-04-01upd. 2024-11-21

In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Bd Pyxis Anesthesia Station Es

    HW
    Bd
    all versions
  • Bd Pyxis Anesthesia Station Es Firmware

    OS
    Bd
    1.6.1
  • Bd Pyxis Medstation Es

    HW
    Bd
    all versions
  • Bd Pyxis Medstation Es Firmware

    OS
    Bd
    1.6.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-22767HIGH8.8same product

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these...

CVE-2022-22766HIGH7.0same product

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain ...

CVE-2019-10959CRITICAL10.0PL ✓same vendor

BD Alaris Gateway Workstation — upload złośliwego firmware bez ograniczeń

CVE-2018-14786CRITICAL9.4PL ✓same vendor

Auth Bypass w pompach strzykawkowych BD Alaris — nieautoryzowany zdalny dostęp

CVE-2017-6022CRITICAL9.8PL ✓same vendor

Hard-coded password w BD PerformA i KLA Journal Service — dostęp do bazy BD Kiestra