VulnerabilityModified
CVE-2018-10631
The 8840 Clinician Programmer executes the application program from the 8870 Application Card.
MEDIUM 6.3EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-693
- Affected
- medtronic/n\'vision 8840 firmware · medtronic/n\'vision 8870 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/104213
- https://global.medtronic.com/xg-en/product-security/security-bulletins/nvision.html
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01Third Party Advisory, US Government Resource
- https://www.medtronic.com/securityVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01Third Party Advisory, US Government Resource
- https://www.medtronic.com/securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.