CVE-2018-18976: Ascensia Contour Diabetes

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user ID values. (This information can be decrypted through a different vulnerability.)

Affected products

  • Ascensia Contour Diabetes: before 2.4.30 (fixed in 2.4.30); before 2.5.0 (fixed in 2.5.0)

Published 2019-05-06. Last modified 2026-06-17.