CVE-2019-18256

MEDIUM

BIOTRONIK CardioMessenger II - Info Disclosure

Title source: llm

Description

BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.

Scores

CVSS v3 4.6
EPSS 0.0006
EPSS Percentile 17.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522 CWE-257
Status published

Affected Products (2)

biotronik/cardiomessenger_ii-s_gsm_firmware
biotronik/cardiomessenger_ii-s_t-line_firmware

Timeline

Published Jun 29, 2020
Tracked Since Feb 18, 2026