CVE-2020-10598 Vulnerability Details

  /     /     /  

CVE-2020-10598 Metadata Quick Info

CVE Published: 01/04/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: icscert | Vendor: Becton, Dickinson and Company (BD) | Product: Pyxis MedStation ES System
Status : PUBLISHED

CVE-2020-10598 Description

In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-693
CWE Name: PROTECTION MECHANISM FAILURE CWE-693
Source: Becton, Dickinson and Company (BD)

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).