PT-2019-9680 · Ascensia · Ascensia Contour Next One

Publicado

2019-05-06

·

Atualizado

2020-08-24

·

CVE-2018-18976

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ascensia Contour NEXT ONE application for iOS and Android versions prior to 2019-01-15
Description The issue allows an attacker to retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user id values. This information can be decrypted through a different issue.
Recommendations For versions prior to 2019-01-15, update to a version released after 2019-01-15 to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoint to minimize the risk of exploitation. Avoid using the user id parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18976

Produtos afetados

Ascensia Contour Next One