CVE-2018-18975
- EPSS 0.21%
- Veröffentlicht 06.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:57
An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Ascensia backend servers because of a weak certificate-pinning implementation, leading to disclosure of m...
CVE-2018-18976
- EPSS 0.21%
- Veröffentlicht 06.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:58
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with ...
CVE-2018-18977
- EPSS 0.32%
- Veröffentlicht 06.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:58
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to extract sensitive data that contributes to the disclosure of medical information of patients utilizin...
CVE-2018-18978
- EPSS 0.18%
- Veröffentlicht 06.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:58
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and th...
CVE-2018-18979
- EPSS 0.34%
- Veröffentlicht 06.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:58
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this appl...