CVE-2018-18562
HIGH
8,8
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
LOW
3,3
Source: [email protected]
Access Vector: adjacent_network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none
Description
AI Translation Available
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unauthorized service access via a service interface.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0022
Percentile
0,4th
Updated
EPSS Score Trend (Last 91 Days)
521
Weak Password Requirements
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
Operating System
Cobas H 232 Firmware by Roche
Version Range Affected
To
03.01.04
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:roche:cobas_h_232_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Base Unit Hub Firmware by Roche
Version Range Affected
To
03.01.04
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:roche:base_unit_hub_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Accu-Chek Inform Ii Firmware by Roche
Version Range Affected
To
03.01.04
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:roche:accu-chek_inform_ii_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Coaguchek Firmware by Roche
Version Range Affected
To
03.01.04
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:roche:coaguchek_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://ics-cert.us-cert.gov/advisories/ICSMA-18-310-01
http://www.securityfocus.com/bid/105843
https://ics-cert.us-cert.gov/advisories/ICSMA-18-310-01
http://www.securityfocus.com/bid/105843