CVE-2018-18984

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
14/12/2018
Last modified:
22/05/2025

Description

Medtronic CareLink and Encore Programmers<br /> <br /> do not encrypt or do not sufficiently encrypt sensitive <br /> PII and PHI information while at rest .

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_2090_programmer:-:*:*:*:*:*:*:*
cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:carelink_9790_programmer:-:*:*:*:*:*:*:*
cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:29901_encore_programmer:-:*:*:*:*:*:*:*