HIGH · 7.1

CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless...

Vulnerability Description

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MedtronicMinimed 508 FirmwareAll versions
MedtronicMinimed 508-
MedtronicMinimed Paradigm 511 FirmwareAll versions
MedtronicMinimed Paradigm 511-
MedtronicMinimed Paradigm 512 FirmwareAll versions
MedtronicMinimed Paradigm 512-
MedtronicMinimed Paradigm 712 FirmwareAll versions
MedtronicMinimed Paradigm 712-
MedtronicMinimed Paradigm 712E FirmwareAll versions
MedtronicMinimed Paradigm 712E-
MedtronicMinimed Paradigm 515 FirmwareAll versions
MedtronicMinimed Paradigm 515-
MedtronicMinimed Paradigm 715 FirmwareAll versions
MedtronicMinimed Paradigm 715-
MedtronicMinimed Paradigm 522 FirmwareAll versions
MedtronicMinimed Paradigm 522-
MedtronicMinimed Paradigm 722 FirmwareAll versions
MedtronicMinimed Paradigm 722-
MedtronicMinimed Paradigm 522K FirmwareAll versions
MedtronicMinimed Paradigm 522K-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10964?

CVE-2019-10964 is a vulnerability with a CVSS score of 7.1 (HIGH). Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless...

How severe is CVE-2019-10964?

CVE-2019-10964 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10964?

Check the references section above for vendor advisories and patch information. Affected products include: Medtronic Minimed 508 Firmware, Medtronic Minimed 508, Medtronic Minimed Paradigm 511 Firmware, Medtronic Minimed Paradigm 511, Medtronic Minimed Paradigm 512 Firmware.