CVE-2019-18252
Summary
| CVE | CVE-2019-18252 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-29 14:15:00 UTC |
| Updated | 2021-04-06 17:16:00 UTC |
| Description | BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Biotronik | Cardiomessenger Ii-s Gsm | - | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s Gsm | - | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s Gsm Firmware | 2.20 | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s Gsm Firmware | 2.20 | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s T-line | - | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s T-line | - | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s T-line Firmware | 2.20 | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s T-line Firmware | 2.20 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BIOTRONIK CardioMessenger II | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.