HIGH · 7.8

CVE-2018-19012

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kios...

Vulnerability Description

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take control of the operating system.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DraegerKappa FirmwareAll versions
DraegerKappa-
DraegerInfinity Explorer C700 FirmwareAll versions
DraegerInfinity Explorer C700-
DraegerDelta Xl FirmwareAll versions
DraegerDelta Xl-
DraegerInfinity Delta FirmwareAll versions
DraegerInfinity Delta-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19012?

CVE-2018-19012 is a vulnerability with a CVSS score of 7.8 (HIGH). Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kios...

How severe is CVE-2018-19012?

CVE-2018-19012 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-19012?

Check the references section above for vendor advisories and patch information. Affected products include: Draeger Kappa Firmware, Draeger Kappa, Draeger Infinity Explorer C700 Firmware, Draeger Infinity Explorer C700, Draeger Delta Xl Firmware.