CVE-2019-18256

MEDIUM

BIOTRONIK CardioMessenger II - Info Disclosure

Title source: llm
STIX 2.1

Description

BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.

Scores

CVSS v3 4.6
EPSS 0.0006
EPSS Percentile 17.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522 CWE-257
Status published
Products (2)
biotronik/cardiomessenger_ii-s_gsm_firmware 2.20
biotronik/cardiomessenger_ii-s_t-line_firmware 2.20
Published Jun 29, 2020
Tracked Since Feb 18, 2026