CVE-2018-18984
14.12.2018, 15:29
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .Enginsight
Vendor | Product | Version |
---|---|---|
medtronic | carelink_2090_programmer_firmware | * |
medtronic | carelink_9790_programmer_firmware | * |
medtronic | 29901_encore_programmer_firmware | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.