CVE-2023-52952

A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436) (All versions >= V11.5.1 < V11.6.2). The Kiosk Mode of the affected devices contains a restricted desktop environment escape vulnerability. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.
Configurations

No configuration.

History

10 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en HiMed Cockpit 12 pro (J31032-K2017-H259) (todas las versiones &gt;= V11.5.1 &lt; V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (todas las versiones &gt;= V11.5.1 &lt; V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (todas las versiones &gt;= V11.5.1 &lt; V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436) (todas las versiones &gt;= V11.5.1 &lt; V11.6.2). El modo quiosco de los dispositivos afectados contiene una vulnerabilidad de escape del entorno de escritorio restringido. Esto podrĂ­a permitir que un atacante local no autenticado escape del entorno restringido y obtenga acceso al sistema operativo subyacente.

08 Oct 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 09:15

Updated : 2024-10-10 12:56


NVD link : CVE-2023-52952

Mitre link : CVE-2023-52952

CVE.ORG link : CVE-2023-52952


JSON object : View

Products Affected

No product.

CWE
CWE-424

Improper Protection of Alternate Path