PT-2020-9952 · Biotronik · Cardiomessenger Ii
Published
2020-06-29
·
Updated
2021-10-29
·
CVE-2019-18254
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
BIOTRONIK CardioMessenger II (affected versions not specified)
Description:
The affected product does not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Encryption of Sensitive Data
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cardiomessenger Ii