Description
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.
Scores
CVSS v3
4.6
EPSS
0.0006
EPSS Percentile
17.2%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-522
CWE-257
Status
published
Products (2)
biotronik/cardiomessenger_ii-s_gsm_firmware
2.20
biotronik/cardiomessenger_ii-s_t-line_firmware
2.20
Published
Jun 29, 2020
Tracked Since
Feb 18, 2026