PT-2024-14789 · Unknown · Himed Cockpit 18 Pro+2
Tamay Caliskan
·
Published
2024-10-08
·
Updated
2024-10-13
·
CVE-2023-52952
CVSS v3.1
8.5
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
HiMed Cockpit 12 pro versions 11.5.1 through 11.6.2
HiMed Cockpit 14 pro+ versions 11.5.1 through 11.6.2
HiMed Cockpit 18 pro versions 11.5.1 through 11.6.2
HiMed Cockpit 18 pro+ versions 11.5.1 through 11.6.2
Description
A restricted desktop environment escape vulnerability has been identified in the Kiosk Mode of the affected devices. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.
Recommendations
For HiMed Cockpit 12 pro versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk.
For HiMed Cockpit 14 pro+ versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk.
For HiMed Cockpit 18 pro versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk.
For HiMed Cockpit 18 pro+ versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the Kiosk Mode until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Himed Cockpit 12 Pro
Himed Cockpit 14 Pro+
Himed Cockpit 18 Pro