Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5024

Опубликовано: 11 апр. 2019
Источник: nvd
CVSS3: 7.6
CVSS3: 7.6
CVSS2: 7.2
EPSS Низкий

Описание

A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:capsuletech:smartlinx_neuron_2_firmware:*:*:*:*:*:*:*:*
Версия до 9.0.3 (включая)
cpe:2.3:h:capsuletech:smartlinx_neuron_2:-:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00049
Низкий

7.6 High

CVSS3

7.6 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-693
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.6
github
почти 4 года назад

A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this vulnerability.

EPSS

Процентиль: 15%
0.00049
Низкий

7.6 High

CVSS3

7.6 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-693
NVD-CWE-noinfo