René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

112 lines
3.6 KiB
JSON

{
"id": "CVE-2018-18976",
"sourceIdentifier": "cve@mitre.org",
"published": "2019-05-06T20:29:00.367",
"lastModified": "2020-08-24T17:37:01.140",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user ID values. (This information can be decrypted through a different vulnerability.)"
},
{
"lang": "es",
"value": "Fue descubierto un fallo en la aplicaci\u00f3n para iOS y Android Ascensia Contour NEXT ONE antes del 15-01-2019. Un atacante podr\u00eda obtener datos m\u00e9dicos cifrados de cualquier paciente de la plataforma en la nube Ascensia realizando Referencias Directas de Objetos con una serie de valores de ID de usuario. (Esta informaci\u00f3n puede ser descifrada a trav\u00e9s de una vulnerabilidad diferente)"
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ascensia:contour_diabetes:*:*:*:*:*:iphone_os:*:*",
"versionEndExcluding": "2.4.30",
"matchCriteriaId": "81E00FDA-5DE8-47F6-A297-FC27A238B511"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ascensia:contour_diabetes:*:*:*:*:*:android:*:*",
"versionEndExcluding": "2.5.0",
"matchCriteriaId": "47844740-F98D-485F-A188-FA9EDF1C88A1"
}
]
}
]
}
],
"references": [
{
"url": "https://depthsecurity.com/blog/medical-exploitation-you-are-now-diabetic",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}