CVE-2018-18984

Published: Dic 14, 2018 Last Modified: Mag 22, 2025 EU-VD ID: EUVD-2018-10688 Aliases: GSD-2018-18984
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,6
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
LOW 2,1
Access Vector: local
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

Medtronic CareLink and Encore Programmers

do not encrypt or do not sufficiently encrypt sensitive
PII and PHI information while at rest .

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0008
Percentile
0,2th
Updated

EPSS Score Trend (Last 90 Days)

311

Missing Encryption of Sensitive Data

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Application Data Modify Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
312

Cleartext Storage of Sensitive Information

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies: Cloud Computing, ICS/OT, Mobile
View CWE Details
Operating System

Carelink 9790 Programmer Firmware by Medtronic

cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

29901 Encore Programmer Firmware by Medtronic

cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Carelink 2090 Programmer Firmware by Medtronic

cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01
Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01
http://www.securityfocus.com/bid/106215
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/106215
https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink…
https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01
Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01
http://www.securityfocus.com/bid/106215
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/106215