CVE-2020-10598

In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsma-20-091-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:bd:pyxis_medstation_es_firmware:1.6.1:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_medstation_es:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bd:pyxis_anesthesia_station_es_firmware:1.6.1:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_anesthesia_station_es:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-04-01 21:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-10598

Mitre link : CVE-2020-10598

CVE.ORG link : CVE-2020-10598


JSON object : View

Products Affected

bd

  • pyxis_medstation_es
  • pyxis_medstation_es_firmware
  • pyxis_anesthesia_station_es
  • pyxis_anesthesia_station_es_firmware
CWE
NVD-CWE-Other CWE-693

Protection Mechanism Failure