CVE-2020-10598
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2020
Last modified:
14/09/2021
Description
In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:bd:pyxis_medstation_es_firmware:1.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:bd:pyxis_medstation_es:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:bd:pyxis_anesthesia_station_es_firmware:1.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:bd:pyxis_anesthesia_station_es:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



