ZeroHour

CVE-2019-18256

CVSS 3.1
4.6 medium
EPSS
<1%p29
Published
()
Modified
Description

BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.

Vendors
biotronik
Products
cardiomessenger ii-s gsm firmware, cardiomessenger ii-s t-line firmware
Weakness
CWE-257, CWE-522
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.