CVE-2019-18254: Biotronik Cardiomessenger Ii-S Gsm Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.

Affected products

  • Biotronik Cardiomessenger Ii-S Gsm Firmware: version 2.20 only
  • Biotronik Cardiomessenger Ii-S T-Line Firmware: version 2.20 only

Published 2020-06-29. Last modified 2026-06-17.