Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-8868

Опубликовано: 03 июл. 2018
Источник: nvd
CVSS3: 6.4
CVSS3: 6.2
CVSS2: 6.9
EPSS Низкий

Описание

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can exploit other vulnerabilities to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:medtronic:24950_mycarelink_monitor_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:24950_mycarelink_monitor:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:medtronic:24952_mycarelink_monitor_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:24952_mycarelink_monitor:-:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

6.4 Medium

CVSS3

6.2 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-749
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.4
github
больше 3 лет назад

Medtronic MyCareLink Patient Monitor, 24950 MyCareLink Monitor, all versions, and 24952 MyCareLink Monitor, all versions, contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can apply the other vulnerabilities within this advisory to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.

EPSS

Процентиль: 15%
0.00048
Низкий

6.4 Medium

CVSS3

6.2 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-749
NVD-CWE-noinfo