PT-2019-17411 · Capsule Technologies · Smartlinx Neuron 2
Published
2019-04-11
·
Updated
2022-06-13
·
CVE-2019-5024
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Capsule Technologies SmartLinx Neuron 2 versions 9.0.3 or lower
Description
A restricted environment escape issue exists in the "kiosk mode" function, allowing an attacker to escape the restricted environment with a specific series of keyboard inputs. This results in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this issue.
Recommendations
For versions 9.0.3 or lower, consider restricting access to the USB port to minimize the risk of exploitation, and avoid using the "kiosk mode" function until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartlinx Neuron 2