CVE-2018-10622
10.08.2018, 18:29
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| medtronic | mycarelink_24952_patient_monitor_firmware | - |
| medtronic | mycarelink_24950_patient_monitor_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-313 - Cleartext Storage in a File or on DiskThe application stores sensitive information in cleartext in a file, or on disk.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References