CVE-2019-5024
Summary
| CVE | CVE-2019-5024 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-11 18:29:00 UTC |
| Updated | 2022-06-13 18:46:00 UTC |
| Description | A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this vulnerability. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Capsuletech | Smartlinx Neuron 2 | - | All | All | All |
| Hardware | Capsuletech | Smartlinx Neuron 2 | - | All | All | All |
| Operating System | Capsuletech | Smartlinx Neuron 2 Firmware | 6.9.1 | All | All | All |
| Operating System | Capsuletech | Smartlinx Neuron 2 Firmware | 6.9.1 | All | All | All |
| Operating System | Capsuletech | Smartlinx Neuron 2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TALOS-2019-0785 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | talosintelligence.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.