René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

154 lines
4.5 KiB
JSON

{
"id": "CVE-2020-10598",
"sourceIdentifier": "ics-cert@hq.dhs.gov",
"published": "2020-04-01T21:15:13.880",
"lastModified": "2021-09-14T13:35:26.183",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data."
},
{
"lang": "es",
"value": "En BD Pyxis MedStation ES System versi\u00f3n v1.6.1 y Pyxis Anesthesia (PAS) ES System versi\u00f3n v1.6.1, presenta una vulnerabilidad de escape de entorno de escritorio restringido en la funcionalidad de kiosk mode de los dispositivos afectados. Unas entradas especialmente dise\u00f1adas pueden permitir al usuario escapar del entorno restringido, resultando en el acceso a datos confidenciales."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.9,
"impactScore": 5.2
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 3.6
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
},
{
"source": "ics-cert@hq.dhs.gov",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-693"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:bd:pyxis_medstation_es_firmware:1.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "D2FB9A03-78B0-4756-B847-94E2B4FC52CD"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:bd:pyxis_medstation_es:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CFB63AC0-5A51-494D-BDFA-BFD4B66A44D9"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:bd:pyxis_anesthesia_station_es_firmware:1.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FD02216F-7EA2-48DF-8C6A-BC9E27367065"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:bd:pyxis_anesthesia_station_es:-:*:*:*:*:*:*:*",
"matchCriteriaId": "32F3ACBB-87CA-43D2-8E32-2656BDCFEB8D"
}
]
}
]
}
],
"references": [
{
"url": "https://www.us-cert.gov/ics/advisories/icsma-20-091-01",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
}
]
}