CVE-2019-10964

Medtronic MiniMed Insulin Pumps

 are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
icscertCNA
7.1 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
medtronicminimed_508_firmware
*
medtronicminimed_paradigm_511_firmware
*
medtronicminimed_paradigm_512_firmware
*
medtronicminimed_paradigm_712_firmware
*
medtronicminimed_paradigm_712e_firmware
*
medtronicminimed_paradigm_515_firmware
*
medtronicminimed_paradigm_715_firmware
*
medtronicminimed_paradigm_522_firmware
*
medtronicminimed_paradigm_722_firmware
*
medtronicminimed_paradigm_522k_firmware
*
medtronicminimed_paradigm_722k_firmware
*
medtronicminimed_paradigm_523_firmware
𝑥
≤ 2.4a
medtronicminimed_paradigm_723_firmware
𝑥
≤ 2.4a
medtronicminimed_paradigm_523k_firmware
𝑥
≤ 2.4a
medtronicminimed_paradigm_723k_firmware
𝑥
≤ 2.4a
medtronicminimed_paradigm_veo_554_firmware
𝑥
≤ 2.6a
medtronicminimed_paradigm_veo_754_firmware
𝑥
≤ 2.6a
medtronicminimed_paradigm_veo_554cm_firmware
𝑥
≤ 2.7a
medtronicminimed_paradigm_veo_754cm_firmware
-
𝑥
= Vulnerable software versions