CVE-2019-18254
Summary
| CVE | CVE-2019-18254 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-29 14:15:00 UTC |
| Updated | 2021-10-29 19:14:00 UTC |
| Description | BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Biotronik | Cardiomessenger Ii-s Gsm | - | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s Gsm | - | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s Gsm Firmware | 2.20 | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s Gsm Firmware | 2.20 | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s T-line | - | All | All | All |
| Hardware | Biotronik | Cardiomessenger Ii-s T-line | - | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s T-line Firmware | 2.20 | All | All | All |
| Operating System | Biotronik | Cardiomessenger Ii-s T-line Firmware | 2.20 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BIOTRONIK CardioMessenger II | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.