CVE-2018-14781

Medtronic MiniMed MMT 

devices when paired with a remote controller and having the easy bolus and remote bolus options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
icscertCNA
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
medtronicdiabetes508_minimed_insulin_pump_firmware
-
medtronicdiabetes522_paradigm_real-time_firmware
-
medtronicdiabetes722_paradigm_real-time_firmware
-
medtronicdiabetes523_paradigm_revel_firmware
-
medtronicdiabetes723_paradigm_revel_firmware
-
medtronicdiabetes523k_paradigm_revel_firmware
-
medtronicdiabetes723k_paradigm_revel_firmware
-
medtronicdiabetes551_minimed_530g_firmware
-
medtronicdiabetes751_minimed_530g_firmware
-
𝑥
= Vulnerable software versions