CVE-2019-18256: Biotronik Cardiomessenger Ii-S Gsm Firmware
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.
Affected products
- Biotronik Cardiomessenger Ii-S Gsm Firmware: version 2.20 only
- Biotronik Cardiomessenger Ii-S T-Line Firmware: version 2.20 only
Published 2020-06-29. Last modified 2026-06-17.