CVE-2019-10964
Medtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access Control
Medtronic MiniMed Insulin Pumps
are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Productos afectados
Medtronic · MiniMed 508 pumpMedtronic · MiniMed Paradigm 511 pumpMedtronic · MiniMed Paradigm 512/712 pumpsMedtronic · MiniMed Paradigm 515/715 pumpsMedtronic · MiniMed Paradigm 522/722 pumpsMedtronic · MiniMed Paradigm 522K/722K pumpsMedtronic · MiniMed Paradigm 523/723 pumpsMedtronic · MiniMed Paradigm 523K/723K pumpsMedtronic · MiniMed Paradigm 712E pumpMedtronic · MiniMed Paradigm Veo 554/754 pumpsMedtronic · MiniMed Paradigm Veo 554CM/754CM pumps¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →