Impact
A flaw in the Restricted Access mode of the Scheidt & Bachmann entervo HMI allows an authenticated user with normally limited rights to break out of the kiosk‑mode sandbox. By opening the on‑device manual with the external PDF viewer and triggering its print function, the user can cause the operating system to run arbitrary commands. The commands execute with the privileges of the local administrator, giving the attacker full control over the host machine.
Affected Systems
The vulnerability is present in all releases of the Scheidt & Bachmann entervo HMI before V2 R5 P0 M5. The affected component is the external PDF viewer subsystem that renders the application manual and interacts with the underlying Windows OS.
Risk and Exploitability
The vulnerability is a local privilege escalation that can be exercised by any logged‑in user who has permission to open the manual. The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, but the potential impact is high because the local admin rights gained allow full system compromise. Exploitation requires only internal access and a user account able to launch the PDF viewer; no network access is needed.
OpenCVE Enrichment