PT-2019-9680 · Ascensia · Ascensia Contour Next One

Published

2019-05-06

·

Updated

2020-08-24

·

CVE-2018-18976

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ascensia Contour NEXT ONE application for iOS and Android versions prior to 2019-01-15
Description The issue allows an attacker to retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user id values. This information can be decrypted through a different issue.
Recommendations For versions prior to 2019-01-15, update to a version released after 2019-01-15 to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoint to minimize the risk of exploitation. Avoid using the user id parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18976

Affected Products

Ascensia Contour Next One