Lucene search

K
nvd[email protected]NVD:CVE-2018-8849
HistoryMay 18, 2018 - 1:29 p.m.

CVE-2018-8849

2018-05-1813:29:00
CWE-311
web.nvd.nist.gov
3

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

38.1%

Medtronic N’Vision Clinician Programmer 8840 N’Vision Clinician Programmer, all versions, and 8870 N’Vision removable Application Card, all versions does not encrypt PII and PHI while at rest.

Affected configurations

Nvd
Node
medtronicn\'vision_8840_firmwareMatch-
AND
medtronicn\'vision_8840Match-
Node
medtronicn\'vision_8870_firmwareMatch-
AND
medtronicn\'vision_8870Match-
VendorProductVersionCPE
medtronicn\'vision_8840_firmware-cpe:2.3:o:medtronic:n\'vision_8840_firmware:-:*:*:*:*:*:*:*
medtronicn\'vision_8840-cpe:2.3:h:medtronic:n\'vision_8840:-:*:*:*:*:*:*:*
medtronicn\'vision_8870_firmware-cpe:2.3:o:medtronic:n\'vision_8870_firmware:-:*:*:*:*:*:*:*
medtronicn\'vision_8870-cpe:2.3:h:medtronic:n\'vision_8870:-:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

38.1%

Related for NVD:CVE-2018-8849