AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-18978

HIGH · CVSS 7.4 EPSS 0.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-06 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. It affects Android.

CVE
CVE-2018-18978
Severity
HIGH
CVSS
7.4
EPSS
0.73%
Android

Original NVD Description

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in combination with retrieving any user's encrypted data from the Ascensia cloud through another vulnerability, allows an attacker to obtain and modify any patient's medical information.

Related CVEs

Other vulnerabilities affecting the same vendor(s)