CVE-2018-18984

Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_2090_programmer:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_9790_programmer:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:29901_encore_programmer:-:*:*:*:*:*:*:*

History

22 May 2025, 17:15

Type Values Removed Values Added
Summary (en) Medtronic CareLink 2090 Programmer CareLink 9790 Programmer 29901 Encore Programmer, all versions, The affected products do not encrypt or do not sufficiently encrypt the following sensitive information while at rest PII and PHI. (en) Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
References
  • () https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-9790-2090-29901.html -

21 Nov 2024, 03:56

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/106215 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/106215 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSMA-18-347-01 - Third Party Advisory, US Government Resource

Information

Published : 2018-12-14 15:29

Updated : 2025-05-22 17:15


NVD link : CVE-2018-18984

Mitre link : CVE-2018-18984

CVE.ORG link : CVE-2018-18984


JSON object : View

Products Affected

medtronic

  • carelink_9790_programmer
  • 29901_encore_programmer_firmware
  • carelink_9790_programmer_firmware
  • 29901_encore_programmer
  • carelink_2090_programmer_firmware
  • carelink_2090_programmer
CWE
CWE-311

Missing Encryption of Sensitive Data

CWE-312

Cleartext Storage of Sensitive Information