A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436) (All versions >= V11.5.1 < V11.6.2). The Kiosk Mode of the affected devices contains a restricted desktop environment escape vulnerability. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.
Kiosk Mode in the affected devices is improperly protected (CWE-424: Improper Protection of Alternate Path), which allows circumvention of imposed environmental restrictions. An attacker with physical or local access to the device can exploit this weakness without needing any authentication credentials. As a result, it is possible to exit the restricted desktop environment and directly interact with the operating system running beneath the kiosk application.
An attacker can gain unauthorized access to the underlying operating system of the medical device, which potentially enables its complete takeover, data modification, or disruption of device operation.
Firmware should be updated to version V11.6.2 or newer. Detailed information and patches are available in the Siemens security bulletin at: https://cert-portal.siemens.com/productcert/html/ssa-540493.html
Siemens HiMed Cockpit 12 pro (J31032-K2017-H259), HiMed Cockpit 14 pro+ (J31032-K2017-H435), HiMed Cockpit 18 pro (J31032-K2017-H260), HiMed Cockpit 18 pro+ (J31032-K2017-H436) — all firmware versions >= V11.5.1 and < V11.6.2
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X