CRITICAL🇵🇱 Wersja polska

CVE-2023-52952

CVSS 9.3v4.0pub. 2024-10-08upd. 2026-04-15

A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436) (All versions >= V11.5.1 < V11.6.2). The Kiosk Mode of the affected devices contains a restricted desktop environment escape vulnerability. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.

🤖 AI Analysis
How it works

Kiosk Mode in the affected devices is improperly protected (CWE-424: Improper Protection of Alternate Path), which allows circumvention of imposed environmental restrictions. An attacker with physical or local access to the device can exploit this weakness without needing any authentication credentials. As a result, it is possible to exit the restricted desktop environment and directly interact with the operating system running beneath the kiosk application.

Impact

An attacker can gain unauthorized access to the underlying operating system of the medical device, which potentially enables its complete takeover, data modification, or disruption of device operation.

Mitigation & patch

Firmware should be updated to version V11.6.2 or newer. Detailed information and patches are available in the Siemens security bulletin at: https://cert-portal.siemens.com/productcert/html/ssa-540493.html

Who is affected

Siemens HiMed Cockpit 12 pro (J31032-K2017-H259), HiMed Cockpit 14 pro+ (J31032-K2017-H435), HiMed Cockpit 18 pro (J31032-K2017-H260), HiMed Cockpit 18 pro+ (J31032-K2017-H436) — all firmware versions >= V11.5.1 and < V11.6.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References