PT-2019-9680 · Ascensia · Ascensia Contour Next One
Publicado
2019-05-06
·
Atualizado
2020-08-24
·
CVE-2018-18976
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ascensia Contour NEXT ONE application for iOS and Android versions prior to 2019-01-15
Description
The issue allows an attacker to retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of
user id values. This information can be decrypted through a different issue.Recommendations
For versions prior to 2019-01-15, update to a version released after 2019-01-15 to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoint to minimize the risk of exploitation. Avoid using the
user id parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ascensia Contour Next One