Vulnerability Description
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Biotronik | Cardiomessenger Ii-S Gsm Firmware | 2.20 |
| Biotronik | Cardiomessenger Ii-S Gsm | - |
| Biotronik | Cardiomessenger Ii-S T-Line Firmware | 2.20 |
| Biotronik | Cardiomessenger Ii-S T-Line | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsma-20-170-05Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-170-05Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-18252?
CVE-2019-18252 is a vulnerability with a CVSS score of 4.3 (MEDIUM). BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials us...
How severe is CVE-2019-18252?
CVE-2019-18252 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18252?
Check the references section above for vendor advisories and patch information. Affected products include: Biotronik Cardiomessenger Ii-S Gsm Firmware, Biotronik Cardiomessenger Ii-S Gsm, Biotronik Cardiomessenger Ii-S T-Line Firmware, Biotronik Cardiomessenger Ii-S T-Line.