PT-2019-9680 · Ascensia · Ascensia Contour Next One
Published
2019-05-06
·
Updated
2020-08-24
·
CVE-2018-18976
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ascensia Contour NEXT ONE application for iOS and Android versions prior to 2019-01-15
Description
The issue allows an attacker to retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of
user id values. This information can be decrypted through a different issue.Recommendations
For versions prior to 2019-01-15, update to a version released after 2019-01-15 to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoint to minimize the risk of exploitation. Avoid using the
user id parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ascensia Contour Next One