Description
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges.
Published: 2026-08-24
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Upgrade
AI Analysis

Impact

A flaw in the Restricted Access mode of the Scheidt & Bachmann entervo HMI allows an authenticated user with normally limited rights to break out of the kiosk‑mode sandbox. By opening the on‑device manual with the external PDF viewer and triggering its print function, the user can cause the operating system to run arbitrary commands. The commands execute with the privileges of the local administrator, giving the attacker full control over the host machine.

Affected Systems

The vulnerability is present in all releases of the Scheidt & Bachmann entervo HMI before V2 R5 P0 M5. The affected component is the external PDF viewer subsystem that renders the application manual and interacts with the underlying Windows OS.

Risk and Exploitability

The vulnerability is a local privilege escalation that can be exercised by any logged‑in user who has permission to open the manual. The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, but the potential impact is high because the local admin rights gained allow full system compromise. Exploitation requires only internal access and a user account able to launch the PDF viewer; no network access is needed.

Generated by OpenCVE AI on August 26, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware update for entervo HMI that includes V2 R5 P0 M5 or later.
  • If an update is not yet available, proactively disable the external PDF viewer or remove print functionality from the kiosk mode.
  • Apply least‑privilege restrictions to accounts that can access the manual, removing rights to use print or execute unmanaged code.

Generated by OpenCVE AI on August 26, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via PDF Viewer Print Functionality in Scheidt & Bachmann entervo HMI
Weaknesses CWE-284
CWE-285

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via PDF Viewer Print Functionality in Scheidt & Bachmann entervo HMI
Weaknesses CWE-284
CWE-285

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via PDF Viewer Print Function in Scheidt & Bachmann entervo HMI
Weaknesses CWE-28
CWE-78

Mon, 24 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via PDF Viewer Print Function in Scheidt & Bachmann entervo HMI
Weaknesses CWE-28
CWE-78

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in Entevo HMI V2 R5 P0 M4 allows attackers to escape Kiosk Mode by opening the application manual in an external PDF viewer and abusing the Print functionality to access Windows Explorer and execute arbitrary commands with administrative privileges. A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges.

Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in Entevo HMI V2 R5 P0 M4 allows attackers to escape Kiosk Mode by opening the application manual in an external PDF viewer and abusing the Print functionality to access Windows Explorer and execute arbitrary commands with administrative privileges.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-25T19:46:32.079Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30512

cve-icon Vulnrichment

Updated: 2026-08-25T19:46:28.937Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T14:16:53.453

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-30512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T05:30:18Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges