CVE-2018-18563

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

9.6critical3.x
0246810

CVSS Score: 9.6/10

All CVSS Scores

CVSS 3.x
9.6

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS 2.0
8.3

Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Description

An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before 03.01.06, cobas h 232 before 03.01.03 (Serial Number below KQ0400000 or KS0400000) and cobas h 232 before 04.00.04 (Serial Number above KQ0400000 or KS0400000). Improper access control to a service command allows attackers in the adjacent network to execute arbitrary code on the system through a crafted Poct1-A message.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-434

Vulnerable Software (5)

Type: Configuration

Vendor: roche

Product: accu-chek_inform_ii_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:roche:accu-chek_inform_ii_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "03.06.00",          "vul...

Source: nvd

Type: Configuration

Vendor: roche

Product: coaguchek_pro_ii_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:roche:coaguchek_pro_ii_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "04.03.00",          "vulner...

Source: nvd

Type: Configuration

Vendor: roche

Product: coaguchek_xs_plus_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:roche:coaguchek_xs_plus_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "03.01.06",          "vulne...

Source: nvd

Type: Configuration

Vendor: roche

Product: coaguchek_xs_pro_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:roche:coaguchek_xs_pro_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "03.01.06",          "vulner...

Source: nvd

Type: Configuration

Vendor: roche

Product: cobas_h_232_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:roche:cobas_h_232_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "03.01.03",          "vulnerable"...

Source: nvd