PT-2020-16666 · Medtronic · Medtronic Mycarelink Smart 25000+1

Published

2020-12-14

·

Updated

2020-12-15

·

CVE-2020-27252

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medtronic MyCareLink Smart 25000 all versions
Description The issue concerns a race condition in the MCL Smart Patient Reader software update system, allowing unsigned firmware to be uploaded and executed. This could enable an attacker to remotely execute code on the device, potentially leading to device control.
Recommendations For Medtronic MyCareLink Smart 25000 all versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27252

Affected Products

Mcl Smart Patient Reader
Medtronic Mycarelink Smart 25000