CVE-2019-6540
26.03.2019, 18:29
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.Enginsight
Vendor | Product | Version |
---|---|---|
medtronic | mycarelink_monitor_24950_firmware | - |
medtronic | mycarelink_monitor_24952_firmware | - |
medtronic | carelink_monitor_2490c_firmware | - |
medtronic | carelink_2090_firmware | - |
medtronic | amplia_crt-d_firmware | - |
medtronic | claria_crt-d_firmware | - |
medtronic | compia_crt-d_firmware | - |
medtronic | concerto_crt-d_firmware | - |
medtronic | concerto_ii_crt-d_firmware | - |
medtronic | consulta_crt-d_firmware | - |
medtronic | evera_icd_firmware | - |
medtronic | maximo_ii_crt-d_firmware | - |
medtronic | maximo_ii_icd_firmware | - |
medtronic | mirro_icd_firmware | - |
medtronic | nayamed_nd_icd_firmware | - |
medtronic | primo_icd_firmware | - |
medtronic | protecta_icd_firmware | - |
medtronic | protecta_crt-d_firmware | - |
medtronic | secura_icd_firmware | - |
medtronic | virtuoso_icd_firmware | - |
medtronic | virtuoso_ii_icd_firmware | - |
medtronic | visia_af_icd_firmware | - |
medtronic | viva_crt-d_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration