← Back

CVE-2018-18565

nvd nist
Published: Nov 20, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Exploitability: 2.3 / Impact: 4.0
Source: NVD

Description

An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before 03.01.06, cobas h 232 before 03.01.03 (Serial number below KQ0400000 or KS0400000), and cobas h 232 before 04.00.04 (Serial number above KQ0400000 or KS0400000). A vulnerability in the software update mechanism allows authenticated attackers in the adjacent network to overwrite arbitrary files on the system through a crafted update package.

Affected (7)

5 products
Accu Chek Inform Ii Firmware
Cobas H 232 Firmware
Coaguchek Pro Ii Firmware
Coaguchek Xs Plus Firmware
Coaguchek Xs Pro Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Roche
Before 03.06.00
From 04.00.00 to 04.03.00
Running on/withPlatform Versions
Roche
Accu Chek Inform Ii
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Roche
Before 03.01.03
From 04.00.00 to 04.00.04
Running on/withPlatform Versions
Roche
Cobas H 232
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 04.03.00
Running on/withPlatform Versions
Roche
Coaguchek Pro Ii
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 03.01.06
Running on/withPlatform Versions
Roche
Coaguchek Xs Plus
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 03.01.06
Running on/withPlatform Versions
Roche
Coaguchek Xs Pro
All versions

References (4)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.