ID

VAR-201712-0254


CVE

CVE-2017-14018


TITLE

Ethicon Endo-Surgery Generator G11 Security Bypass Vulnerability

Trust: 0.8

sources: IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // CNVD: CNVD-2017-35428

DESCRIPTION

An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability. The Ethicon Endo-Surgery Generator G11 is a host of ultrasound HF surgical integrated systems deployed in the healthcare and public health sectors. Ethicon Endo-Surgery Generator G11 is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks. All versions of Ethicon Endo-Surgery Generator Gen11 are vulnerable. Ethicon Endo-Surgery Generator Gen11 is an internal and surgical device produced by Ethicon Endo-Surgery in the United States

Trust: 2.7

sources: NVD: CVE-2017-14018 // JVNDB: JVNDB-2017-011178 // CNVD: CNVD-2017-35428 // BID: 101978 // IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // VULHUB: VHN-104698

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // CNVD: CNVD-2017-35428

AFFECTED PRODUCTS

vendor:ethiconmodel:endo-surgery generator gen11scope:eqversion: -

Trust: 1.6

vendor:ethicon usmodel:endo-surgery generator gen11scope:eqversion:2017-11-29 released before

Trust: 0.8

vendor:ethiconmodel:endo-surgery generator gen11 <novemberscope:eqversion:292017

Trust: 0.6

vendor:ethiconmodel:endo-surgery generator gen11scope: - version: -

Trust: 0.3

vendor:endo surgery generator gen11model: - scope:eqversion: -

Trust: 0.2

sources: IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // CNVD: CNVD-2017-35428 // BID: 101978 // JVNDB: JVNDB-2017-011178 // CNNVD: CNNVD-201708-1257 // NVD: CVE-2017-14018

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-14018
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-14018
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-35428
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201708-1257
value: MEDIUM

Trust: 0.6

IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1
value: MEDIUM

Trust: 0.2

VULHUB: VHN-104698
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-14018
severity: LOW
baseScore: 3.3
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-35428
severity: MEDIUM
baseScore: 5.3
vectorString: AV:A/AC:H/AU:N/C:N/I:C/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 3.2
impactScore: 7.8
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1
severity: MEDIUM
baseScore: 5.3
vectorString: AV:A/AC:H/AU:N/C:N/I:C/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 3.2
impactScore: 7.8
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-104698
severity: LOW
baseScore: 3.3
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-14018
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 0.5
impactScore: 4.2
version: 3.0

Trust: 1.8

sources: IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // CNVD: CNVD-2017-35428 // VULHUB: VHN-104698 // JVNDB: JVNDB-2017-011178 // CNNVD: CNNVD-201708-1257 // NVD: CVE-2017-14018

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-104698 // JVNDB: JVNDB-2017-011178 // NVD: CVE-2017-14018

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201708-1257

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201708-1257

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-011178

PATCH

title:Top Pageurl:https://www.ethicon.com/na/

Trust: 0.8

title:Ethicon Endo-Surgery Generator G11 Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76735

Trust: 0.6

sources: JVNDB: JVNDB-2017-011178 // CNNVD: CNNVD-201708-1257

EXTERNAL IDS

db:NVDid:CVE-2017-14018

Trust: 3.6

db:ICS CERTid:ICSMA-17-332-01

Trust: 3.4

db:BIDid:101978

Trust: 2.0

db:CNNVDid:CNNVD-201708-1257

Trust: 0.9

db:CNVDid:CNVD-2017-35428

Trust: 0.8

db:JVNDBid:JVNDB-2017-011178

Trust: 0.8

db:IVDid:E2DEBDAF-39AB-11E9-9EA5-000C29342CB1

Trust: 0.2

db:VULHUBid:VHN-104698

Trust: 0.1

sources: IVD: e2debdaf-39ab-11e9-9ea5-000c29342cb1 // CNVD: CNVD-2017-35428 // VULHUB: VHN-104698 // BID: 101978 // JVNDB: JVNDB-2017-011178 // CNNVD: CNNVD-201708-1257 // NVD: CVE-2017-14018

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsma-17-332-01

Trust: 3.4

url:http://www.securityfocus.com/bid/101978

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14018

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-14018

Trust: 0.8

url:http://www.ethicon.com

Trust: 0.3

sources: CNVD: CNVD-2017-35428 // VULHUB: VHN-104698 // BID: 101978 // JVNDB: JVNDB-2017-011178 // CNNVD: CNNVD-201708-1257 // NVD: CVE-2017-14018

CREDITS

The vendor reported the issue.

Trust: 0.3

sources: BID: 101978

SOURCES

db:IVDid:e2debdaf-39ab-11e9-9ea5-000c29342cb1
db:CNVDid:CNVD-2017-35428
db:VULHUBid:VHN-104698
db:BIDid:101978
db:JVNDBid:JVNDB-2017-011178
db:CNNVDid:CNNVD-201708-1257
db:NVDid:CVE-2017-14018

LAST UPDATE DATE

2025-04-20T23:42:54.359000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-35428date:2017-11-29T00:00:00
db:VULHUBid:VHN-104698date:2019-10-09T00:00:00
db:BIDid:101978date:2017-12-19T22:37:00
db:JVNDBid:JVNDB-2017-011178date:2018-01-10T00:00:00
db:CNNVDid:CNNVD-201708-1257date:2019-10-17T00:00:00
db:NVDid:CVE-2017-14018date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:e2debdaf-39ab-11e9-9ea5-000c29342cb1date:2017-11-29T00:00:00
db:CNVDid:CNVD-2017-35428date:2017-11-29T00:00:00
db:VULHUBid:VHN-104698date:2017-12-05T00:00:00
db:BIDid:101978date:2017-11-28T00:00:00
db:JVNDBid:JVNDB-2017-011178date:2018-01-10T00:00:00
db:CNNVDid:CNNVD-201708-1257date:2017-11-28T00:00:00
db:NVDid:CVE-2017-14018date:2017-12-05T23:29:00.217