CVE-2018-10596 Vulnerability Details

  /     /     /  

CVE-2018-10596 Metadata Quick Info

CVE Published: 02/07/2018 | CVE Updated: 16/09/2024 | CVE Year: 2018
Source: icscert | Vendor: ICS-CERT | Product: Medtronic 2090 CareLink Programmer
Status : PUBLISHED

CVE-2018-10596 Description

Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private network connection to securely download updates. The product does not verify it is still connected to this virtual private network before downloading updates. An attacker with local network access to the programmer could influence these communications.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-923
CWE Name: IMPROPER RESTRICTION OF COMMUNICATION CHANNEL TO INTENDED ENDPOINTS CWE-923
Source: ICS-CERT

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).