CVE-2018-18984

Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_2090_programmer:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_9790_programmer:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:29901_encore_programmer:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-12-14 15:29

Updated : 2025-05-22 17:15


NVD link : CVE-2018-18984

Mitre link : CVE-2018-18984

CVE.ORG link : CVE-2018-18984


JSON object : View

Products Affected

medtronic

  • carelink_2090_programmer
  • 29901_encore_programmer
  • carelink_2090_programmer_firmware
  • carelink_9790_programmer
  • 29901_encore_programmer_firmware
  • carelink_9790_programmer_firmware
CWE
CWE-311

Missing Encryption of Sensitive Data

CWE-312

Cleartext Storage of Sensitive Information