CVE-2018-18565

Published Nov 20, 2018

Last updated 4 days ago

Overview

Description
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before 03.01.06, cobas h 232 before 03.01.03 (Serial number below KQ0400000 or KS0400000), and cobas h 232 before 04.00.04 (Serial number above KQ0400000 or KS0400000). A vulnerability in the software update mechanism allows authenticated attackers in the adjacent network to overwrite arbitrary files on the system through a crafted update package.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 3.0

Type
Primary
Base score
6.8
Impact score
4
Exploitability score
2.3
Vector string
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.1
Impact score
4.9
Exploitability score
5.1
Vector string
AV:A/AC:L/Au:S/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-434

Social media

Hype score
Not currently trending

Configurations