PT-2024-14789 · Unknown · Himed Cockpit 18 Pro+2

Tamay Caliskan

·

Published

2024-10-08

·

Updated

2024-10-13

·

CVE-2023-52952

CVSS v3.1

8.5

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions HiMed Cockpit 12 pro versions 11.5.1 through 11.6.2 HiMed Cockpit 14 pro+ versions 11.5.1 through 11.6.2 HiMed Cockpit 18 pro versions 11.5.1 through 11.6.2 HiMed Cockpit 18 pro+ versions 11.5.1 through 11.6.2
Description A restricted desktop environment escape vulnerability has been identified in the Kiosk Mode of the affected devices. This could allow an unauthenticated local attacker to escape the restricted environment and gain access to the underlying operating system.
Recommendations For HiMed Cockpit 12 pro versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk. For HiMed Cockpit 14 pro+ versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk. For HiMed Cockpit 18 pro versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk. For HiMed Cockpit 18 pro+ versions 11.5.1 through 11.6.2, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the Kiosk Mode until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-52952

Affected Products

Himed Cockpit 12 Pro
Himed Cockpit 14 Pro+
Himed Cockpit 18 Pro