Back

HIGH

Medtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access Control

Published Jun 28, 2019

Description

Medtronic MiniMed Insulin Pumps

are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

Affected products

Remediation

Vendor solution

Medtronic recommends U.S. patients who are currently using the affected products talk to their healthcare provider about changing to a newer model insulin pump with increased cybersecurity protection. Patients outside the U.S. will receive a notification letter with instructions based on the country where they live.

Medtronic recommends all patients take the cybersecurity precautions indicated below.

CYBERSECURITY PRECAUTIONS RECOMMENDED FOR ALL PATIENTS:

* Maintain tight physical control of the pump and devices connected to the pump * Do not share pump serial number * Be attentive to pump notifications, alarms, and alerts * Immediately cancel any unintended boluses (a single dose of insulin administered all at once) * Do not connect to any third-party devices or use any software not authorized by Medtronic * Disconnect CareLink USB devices from computers when not being used to download data from the pump * Monitor blood glucose levels closely and act as appropriate * Get medical help immediately when experiencing symptoms of severe hypoglycemia or diabetic ketoacidosis, or suspect an insulin pump settings, or insulin delivery have changed unexpectedly

Medtronic has released additional patient-focused information, at the following location:

https://www.medtronic.com/security

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jun 28, 2019
Updated May 22, 2025
Reserved Apr 8, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Jun 28, 2019
Updated May 22, 2025
Exploited since n/a
EUVD-2019-2678