Biotronik manufactures cardiac implantable medical devices and associated remote monitoring platforms, with its disclosed vulnerabilities concentrating in the CardiomMessenger II remote-monitoring system across its GSM and T-Line variants. The recurring weakness classes—improper authentication, cleartext storage and transmission of sensitive information, and insufficiently protected credentials—reflect the authentication and data-protection demands of connected medical devices that handle patient health records and device-control communications. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Biotronik over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18256MEDIUM BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMes | Jun 29, 2020 | 4.6 | 19 | NO | NO |
CVE-2019-18254MEDIUM BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical | Jun 29, 2020 | 4.6 | 19 | NO | NO |
CVE-2019-18252MEDIUM BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclos | Jun 29, 2020 | 4.3 | 18 | NO | NO |
CVE-2019-18248MEDIUM BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the produc | Jun 29, 2020 | 4.3 | 18 | NO | NO |
CVE-2019-18246MEDIUM BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure. | Jun 29, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Biotronik.
Media articles that mention a CVE ID that affects a product developed by Biotronik — matched by CVE ID, not by vendor name.