René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

189 lines
5.2 KiB
JSON

{
"id": "CVE-2018-18984",
"sourceIdentifier": "ics-cert@hq.dhs.gov",
"published": "2018-12-14T15:29:00.700",
"lastModified": "2020-09-18T16:54:07.023",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, all versions, The affected products do not encrypt or do not sufficiently encrypt the following sensitive information while at rest PII and PHI."
},
{
"lang": "es",
"value": "Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, en todas las versiones. Los productos afectados no cifran, o no cifran lo suficiente la siguiente informaci\u00f3n sensible PII y PHI cuando est\u00e1 en reposo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.6,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
},
{
"source": "ics-cert@hq.dhs.gov",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E80013FE-B9BD-456F-85D3-41C5532AD948"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:carelink_2090_programmer:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7DAB7778-4921-4953-ACAA-ADE2DD773B0D"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "74F4132F-F114-4F2D-9ED8-1A6025F3CBF0"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:carelink_9790_programmer:-:*:*:*:*:*:*:*",
"matchCriteriaId": "97833F56-AD06-42B5-96CF-39551807EDAA"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D9D51AA0-C5D7-472E-A95F-5087BAA30B08"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:29901_encore_programmer:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1A94C34F-2334-40CF-867E-F1FD884F46BE"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/106215",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
}
]
}