Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10631

Опубликовано: 13 июл. 2018
Источник: nvd
CVSS3: 6.8
CVSS3: 6.3
CVSS2: 4.6
EPSS Низкий

Описание

The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:medtronic:n\'vision_8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:n\'vision_8840:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:medtronic:n\'vision_8870_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:n\'vision_8870:-:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00152
Низкий

6.8 Medium

CVSS3

6.3 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-693
CWE-693

Связанные уязвимости

CVSS3: 6.8
github
больше 3 лет назад

Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programmer, all versions, and 8870 N'Vision removable Application Card, all versions. The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.

EPSS

Процентиль: 36%
0.00152
Низкий

6.8 Medium

CVSS3

6.3 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-693
CWE-693