← back
CVE-2020-10598CWE-693

CVE-2020-10598

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
In short

BD Pyxis medical devices running version 1.6.1 have a security flaw that allows users to break out of the restricted kiosk mode by sending specially crafted inputs, potentially exposing sensitive patient data and system information.

Technical detail

A restricted desktop environment escape vulnerability exists in the kiosk mode of BD Pyxis MedStation ES and Pyxis Anesthesia ES v1.6.1, where an authenticated local user can exploit specially crafted inputs to bypass confinement controls and gain unauthorized access to sensitive data on the device.

Summary generated and translated by AI from the official description.
In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.