Vulnerability Description
In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bd | Pyxis Medstation Es Firmware | 1.6.1 |
| Bd | Pyxis Medstation Es | - |
| Bd | Pyxis Anesthesia Station Es Firmware | 1.6.1 |
| Bd | Pyxis Anesthesia Station Es | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsma-20-091-01Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-091-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-10598?
CVE-2020-10598 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. S...
How severe is CVE-2020-10598?
CVE-2020-10598 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10598?
Check the references section above for vendor advisories and patch information. Affected products include: Bd Pyxis Medstation Es Firmware, Bd Pyxis Medstation Es, Bd Pyxis Anesthesia Station Es Firmware, Bd Pyxis Anesthesia Station Es.