First published: Wed Apr 01 2020(Updated: )
In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bd Pyxis Medstation Es Firmware | =1.6.1 | |
BD Pyxis MedStation ES | ||
Bd Pyxis Anesthesia Station Es Firmware | =1.6.1 | |
Bd Pyxis Anesthesia Station Es |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the restricted desktop environment escape vulnerability on BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1 is CVE-2020-10598.
The severity rating of CVE-2020-10598 is medium with a CVSS score of 6.1.
BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1 are affected by CVE-2020-10598.
The vulnerability can be exploited by using specially crafted inputs to escape the restricted environment of the affected devices.
It is recommended to update the affected systems to a patched version provided by BD to mitigate the restricted desktop environment escape vulnerability.