PT-2018-18678 · Medtronic · Medtronic Mycarelink Patient Monitor+2
Publicado
2018-07-02
·
Atualizado
2019-10-09
·
CVE-2018-8868
CVSS v3.1
6.2
Média
| Vetor | AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Medtronic MyCareLink Patient Monitor versions all
Medtronic 24950 MyCareLink Monitor versions all
Medtronic 24952 MyCareLink Monitor versions all
Description
The issue concerns debug code in the Medtronic MyCareLink Patient Monitor and specific MyCareLink Monitor models, which is meant to test communication interfaces, including those between the monitor and implantable cardiac devices. An attacker with physical access to the device can exploit this debug functionality to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. This can be done by an attacker in close physical proximity to a target implantable cardiac device.
Recommendations
For Medtronic MyCareLink Patient Monitor versions all, consider disabling the debug functionality until a patch is available.
For Medtronic 24950 MyCareLink Monitor versions all, restrict access to the debug interface to minimize the risk of exploitation.
For Medtronic 24952 MyCareLink Monitor versions all, avoid using the debug functionality in environments where implantable cardiac devices are used until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Medtronic 24950 Mycarelink Monitor
Medtronic 24952 Mycarelink Monitor
Medtronic Mycarelink Patient Monitor