CVE-2019-13517 describes a vulnerability in BD Pyxis ES (versions 1.3.4-1.6.1) and Pyxis Enterprise Server (versions 4.4-4.12) where expired Active Directory user account changes do not properly restrict existing access privileges when the device is joined to an AD domain. This high-severity vulnerability (CVSS 8.8) allows an authenticated attacker to maintain unauthorized access, potentially leading to full compromise of confidentiality, integrity, and availability. While the attack complexity is low, there is no known public exploit code, Metasploit module, or significant community discussion or media coverage, indicating a low exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4, <= 4.12CPE matchmatch criteria | cpe:2.3:a:bd:pyxis_enterprise_server:*:*:*:*:*:*:*:* | ||
>= 1.3.4, <= 1.6.1CPE matchmatch criteria | cpe:2.3:a:bd:pyxis_es:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.