Vulnerability in Medtronic N'Vision Clinician Programmer and Application Card
CVE-2018-10631

6.3MEDIUM

What is CVE-2018-10631?

The vulnerability affects the Medtronic N'Vision Clinician Programmer 8840 and the 8870 N'Vision removable Application Card. The 8840 Clinician Programmer executes application programs from the removable 8870 Application Card. If an attacker gains physical access to the 8870 Application Card, they can modify its contents, including executable binaries. Such alterations can enable the execution of malicious code without proper authorization when the compromised card is inserted into the 8840 Clinician Programmer, potentially leading to unauthorized access and system compromise.

Affected Version(s)

8840 N’Vision Clinician Programmer All versions

8870 N’Vision removable Application Card All versions

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.