PT-2018-14515 · Roche · Accu-Chek Inform Ii Base Unit+2
Published
2018-11-20
·
Updated
2020-08-24
·
CVE-2018-18561
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roche Accu-Chek Inform II Base Unit / Base Unit Hub versions prior to 03.01.04
Roche CoaguChek / cobas h232 Handheld Base Unit versions prior to 03.01.04
Description
The issue is related to insecure permissions in a service interface, which may allow authenticated attackers in the adjacent network to execute arbitrary commands on the operating system.
Recommendations
For Roche Accu-Chek Inform II Base Unit / Base Unit Hub versions prior to 03.01.04, update to version 03.01.04 or later.
For Roche CoaguChek / cobas h232 Handheld Base Unit versions prior to 03.01.04, update to version 03.01.04 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accu-Chek Inform Ii Base Unit
Coaguchek
Cobas H232 Handheld Base Unit