PT-2020-9952 · Biotronik · Cardiomessenger Ii

Published

2020-06-29

·

Updated

2021-10-29

·

CVE-2019-18254

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: BIOTRONIK CardioMessenger II (affected versions not specified)
Description: The affected product does not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18254

Affected Products

Cardiomessenger Ii