← Back

CVE-2019-18254

nvd nist
Published: Jun 29, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD

Description

BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.

Affected (2)

2 products
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.20
Running on/withPlatform Versions
Biotronik
Cardiomessenger Ii S Gsm
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.20
Running on/withPlatform Versions
Biotronik
Cardiomessenger Ii S T Line
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.