Medtronic MiniMed MMT-500/MMT-503 Remote Controllers Authentication Bypass by Capture-replay
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
Medtronic MiniMed MMT
devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
Medtronic · MMT- 508 - MiniMed pumpMedtronic · MMT – 511 pump ParadigmMedtronic · MMT – 512 / MMT – 712 Paradigm x12Medtronic · MMT – 515 / MMT – 715 Paradigm x15Medtronic · MMT – 522(K) / MMT – 722(K) Paradigm REAL-TIMEMedtronic · MMT – 522 / MMT – 722 Paradigm REAL-TIMEMedtronic · MMT – 523(K) / MMT – 723(K) ParadigmMedtronic · MMT – 523 / MMT – 723 Paradigm RevelMedtronic · MMT – 551 / MMT – 751 MiniMed 530GMedtronic · MMT – 554 / MMT – 754 MiniMed Veo