CVE-2019-10964
8.8
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Medtronic MiniMed Insulin Pumps
are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
Affected (19)
Products: Medtronic: Minimed 508 Firmware, Minimed Paradigm 511 Firmware, Minimed Paradigm 512 Firmware, Minimed Paradigm 712 Firmware, Minimed Paradigm 712e Firmware, Minimed Paradigm 515 Firmware, Minimed Paradigm 715 Firmware, Minimed Paradigm 522 Firmware, Minimed Paradigm 722 Firmware, Minimed Paradigm 522k Firmware, Minimed Paradigm 722k Firmware, Minimed Paradigm 523 Firmware, Minimed Paradigm 723 Firmware, Minimed Paradigm 523k Firmware, Minimed Paradigm 723k Firmware, Minimed Paradigm Veo 554 Firmware, Minimed Paradigm Veo 754 Firmware, Minimed Paradigm Veo 554cm Firmware, Minimed Paradigm Veo 754cm Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed 508 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 511 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 512 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 712 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 712e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 515 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 715 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 522 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 722 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 522k | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 722k | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.4a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 523 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.4a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 723 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.4a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 523k | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.4a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm 723k | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm Veo 554 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm Veo 754 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.7a |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm Veo 554cm | Up to 2.7a |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Medtronic Minimed Paradigm Veo 754cm | All versions |
Related CWEs
CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (5)
Source: ics-cert@hq.dhs.gov
Source: ics-cert@hq.dhs.gov
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.