VYPR
Unrated severityNVD Advisory· Published Nov 20, 2018· Updated Aug 5, 2024

CVE-2018-18561

CVE-2018-18561

Description

Insecure permissions in Roche Accu-Chek Inform II and CoaguChek base units allow adjacent attackers to execute arbitrary commands via the service interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insecure permissions in Roche Accu-Chek Inform II and CoaguChek base units allow adjacent attackers to execute arbitrary commands via the service interface.

Vulnerability

The vulnerability exists in the service interface of Roche Accu-Chek Inform II Base Unit / Base Unit Hub and CoaguChek / cobas h232 Handheld Base Unit. Insecure permissions combined with weak access credentials (Improper Authentication, CWE-287) enable attackers to execute arbitrary commands on the operating system. Affected versions are all versions before 03.01.04 for both product lines. [1]

Exploitation

An attacker in the adjacent network can exploit the service interface without authentication (or using weak credentials) due to improper authentication. Once access is gained, insecure permissions allow the attacker to execute arbitrary OS commands. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the operating system, potentially modifying system settings or executing arbitrary code. This compromises the confidentiality, integrity, and availability of the device. [1]

Mitigation

Roche has released firmware version 03.01.04 to address the vulnerability. Users should update to this version or later. The Accu-Chek Inform II Base Unit Light and Base Unit NEW with software 04.00.00 or newer are not affected. No workarounds are mentioned. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.