CVE-2018-10631
Severity CVSS v4.0:
Pending analysis
Type:
CWE-693
Protection Mechanism Failure
Publication date:
13/07/2018
Last modified:
26/08/2025
Description
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:medtronic:n\'vision_8840_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:medtronic:n\'vision_8840:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:medtronic:n\'vision_8870_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:medtronic:n\'vision_8870:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/104213
- https://global.medtronic.com/xg-en/product-security/security-bulletins/nvision.html
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01
- https://www.medtronic.com/security
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01
- https://www.medtronic.com/security



