cvelist/2018/18xxx/CVE-2018-18984.json

68 lines
1.9 KiB
JSON
Raw Normal View History

2018-11-06 09:04:03 -05:00
{
"CVE_data_meta" : {
"ASSIGNER" : "ics-cert@hq.dhs.gov",
2018-11-06 09:04:03 -05:00
"ID" : "CVE-2018-18984",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer",
"version" : {
"version_data" : [
{
"version_value" : "All versions"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
2018-11-06 09:04:03 -05:00
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, all versions, The affected products do not encrypt or do not sufficiently encrypt the following sensitive information while at rest PII and PHI."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "MISSING ENCRPTION OF SENSITIVE DATA CWE-311"
}
]
}
]
},
"references" : {
"reference_data" : [
{
2018-12-14 10:05:53 -05:00
"name" : "https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01",
"refsource" : "MISC",
"url" : "https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01"
2018-12-17 06:07:53 -05:00
},
{
"name" : "106215",
"refsource" : "BID",
"url" : "http://www.securityfocus.com/bid/106215"
2018-11-06 09:04:03 -05:00
}
]
}
}