CVE-2023-52952
Published: Oct 8, 2024
Modified: Oct 8, 2024
CVSS v3.1
8.5
Description
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436) (All versions >= V11.5.1 < V11.6.2). The Kiosk Mode of the affected devices contains a restricted desktop environment escape vulnerability. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.
| Vendor | Product | Versions |
|---|---|---|
Siemens | HiMed Cockpit 12 pro | affected V11.5.1 - < V11.6.2 |
Siemens | HiMed Cockpit 14 pro+ | affected V11.5.1 - < V11.6.2 |
Siemens | HiMed Cockpit 18 pro | affected V11.5.1 - < V11.6.2 |
Siemens | HiMed Cockpit 18 pro+ | affected V11.5.1 - < V11.6.2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now