CVE-2018-8849

Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:medtronic:n\'vision_8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:n\'vision_8840:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:medtronic:n\'vision_8870_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:n\'vision_8870:-:*:*:*:*:*:*:*

History

27 Jun 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-18-137-01 -
  • () https://www.medtronic.com/security -
Summary (en) Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programmer, all versions, and 8870 N'Vision removable Application Card, all versions does not encrypt PII and PHI while at rest. (en) Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.

21 Nov 2024, 04:14

Type Values Removed Values Added
References () http://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/Medtronic-NVision-8840_Security-Bulletin_FINAL.pdf - Vendor Advisory () http://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/Medtronic-NVision-8840_Security-Bulletin_FINAL.pdf - Vendor Advisory
References () http://www.securityfocus.com/bid/104213 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/104213 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01 - Third Party Advisory, US Government Resource

Information

Published : 2018-05-18 13:29

Updated : 2025-06-27 17:15


NVD link : CVE-2018-8849

Mitre link : CVE-2018-8849

CVE.ORG link : CVE-2018-8849


JSON object : View

Products Affected

medtronic

  • n\'vision_8840_firmware
  • n\'vision_8870
  • n\'vision_8870_firmware
  • n\'vision_8840
CWE
CWE-311

Missing Encryption of Sensitive Data