Unspecified vulnerability in Medtronic Paradigm wireless insulin pump 512, 522, 712, and 722 allows remote attackers to modify the delivery of an insulin bolus dose and cause a denial of service (adverse human health effects) via unspecified vectors involving wireless communications and knowledge of the device's serial number, as demonstrated by Jerome Radcliffe at the Black Hat USA conference in August 2011
Published Sep 2, 2011
4.0
MEDIUMCVSS 2.0
EPSS 1.45%
Description
Unspecified vulnerability in Medtronic Paradigm wireless insulin pump 512, 522, 712, and 722 allows remote attackers to modify the delivery of an insulin bolus dose and cause a denial of service (adverse human health effects) via unspecified vectors involving wireless communications and knowledge of the device's serial number, as demonstrated by Jerome Radcliffe at the Black Hat USA conference in August 2011. NOTE: the vendor has disputed the severity of this issue, saying "we believe the risk of deliberate, malicious, or unauthorized manipulation of medical devices is extremely low... we strongly believe it would be extremely difficult for a third-party to wirelessly tamper with your insulin pump... you would be able to detect tones on the insulin pump that weren't intentionally programmed and could intervene accordingly."
Affected products
No data.
- 512
- 522
- 712
- 722
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.45% (0.01450) | 72.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.45% (0.01450) | 69.84th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.11% (0.01107) | 76.60th | v4 (v2025.03.14) |
| Dec 12, 2024 | 3.76% (0.03761) | 92.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.76% (0.03761) | 90.41th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.41% (0.01408) | 72.89th | v2 (v2022.01.01) |
| Mar 2, 2023 | 1.41% (0.01408) | 72.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.41% (0.01408) | 70.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.41% (0.01408) | 49.94th | v2 (v2022.01.01) |
No CWE recorded.
References (8)
- http://sixuntilme.com/blog2/2011/08/hacked_jay_radcliffe_insulin_p.html x_refsource_MISC
- http://www.darkreading.com/security/vulnerabilities/231300312/getting-root-on-the-human-body.html x_refsource_MISC
- http://www.foxnews.com/scitech/2011/08/04/insulin-pumps-vulnerable-to-hacking/?test=faces x_refsource_MISC
- http://www.hanselman.com/blog/HackersCanKillDiabeticsWithInsulinPumpsFromAHalfMileAwayUmNoFactsVsJournalisticFearMongering.aspx x_refsource_MISC
- http://www.informationweek.com/news/security/vulnerabilities/231600265 x_refsource_MISC
- http://www.loop-blog.com/Blog_Full_Post?id=a09C000000Dbz3JIAR x_refsource_MISC
- http://www.scmagazineus.com/black-hat-insulin-pumps-can-be-hacked/article/209106/ x_refsource_MISC
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69643 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.