CVE-2018-10622

CVSS v3 Score
7.1
High
CVSS v2 Score
1.9
Low

Vulnerability Description

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest.

CVSS:7.3(High)

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installatio...

CVSS:6.8(Medium)

The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the ...

CVSS:6.8(Medium)

Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

CVSS:6.8(Medium)

Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

CVSS:6.7(Medium)

Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

CVSS:6.7(Medium)

Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.