#VU26529 Protection Mechanism Failure in Pyxis Anesthesia (PAS) ES and Pyxis MedStation ES System - CVE-2020-10598
Published: April 2, 2020
Pyxis Anesthesia (PAS) ES
Pyxis MedStation ES System
Becton, Dickinson and Company (BD)
Description
The vulnerability allows a local attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the "kiosk mode" functionality. An attacker with physical access can use a specially crafted input, bypass implemented security restrictions and view and/or modify sensitive data.