CVE-2018-18984
Summary
| CVE | CVE-2018-18984 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-14 15:29:00 UTC |
| Updated | 2020-09-18 16:54:00 UTC |
| Description | Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, all versions, The affected products do not encrypt or do not sufficiently encrypt the following sensitive information while at rest PII and PHI. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Medtronic | 29901 Encore Programmer | - | All | All | All |
| Hardware | Medtronic | 29901 Encore Programmer | - | All | All | All |
| Operating System | Medtronic | 29901 Encore Programmer Firmware | All | All | All | All |
| Operating System | Medtronic | 29901 Encore Programmer Firmware | All | All | All | All |
| Hardware | Medtronic | Carelink 2090 Programmer | - | All | All | All |
| Hardware | Medtronic | Carelink 2090 Programmer | - | All | All | All |
| Operating System | Medtronic | Carelink 2090 Programmer Firmware | All | All | All | All |
| Operating System | Medtronic | Carelink 2090 Programmer Firmware | All | All | All | All |
| Hardware | Medtronic | Carelink 9790 Programmer | - | All | All | All |
| Hardware | Medtronic | Carelink 9790 Programmer | - | All | All | All |
| Operating System | Medtronic | Carelink 9790 Programmer Firmware | All | All | All | All |
| Operating System | Medtronic | Carelink 9790 Programmer Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Medtronic CareLink Encore Programmers CVE-2018-18984 Weak Encryption Security Weakness | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Medtronic 9790, 2090 CareLink, and 29901 Encore Programmers | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.