Medtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access Control
Published Jun 28, 2019
7.1
HIGHCVSS 3.1
EPSS 1.23%
Description
Medtronic MiniMed Insulin Pumps
are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<=Software Versions 2.4A
- Version
-
- Version 0StatusaffectedConstraints<=Software Versions 2.4A
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<=Software Versions 2.6A
- Version
-
- Version 0StatusaffectedConstraints<=Software Versions 2.7A
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Medtronic | MiniMed 508 pump | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 511 pump | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 512/712 pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 515/715 pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 522/722 pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 522K/722K pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 523/723 pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 523K/723K pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm 712E pump | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm Veo 554/754 pumps | unaffected |
| ||||||
| Medtronic | MiniMed Paradigm Veo 554CM/754CM pumps | unaffected |
|
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Running on/with
- n/a
Configuration 11
- n/a
Running on/with
- n/a
Configuration 12
- ≤ 2.4a
Running on/with
- n/a
Configuration 13
- ≤ 2.4a
Running on/with
- n/a
Configuration 14
- ≤ 2.4a
Running on/with
- n/a
Configuration 15
- ≤ 2.4a
Running on/with
- n/a
Configuration 16
- ≤ 2.6a
Running on/with
- n/a
Configuration 17
- ≤ 2.6a
Running on/with
- n/a
Configuration 18
- ≤ 2.7a
Running on/with
- ≤ 2.7a
Configuration 19
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Medtronic recommends U.S. patients who are currently using the affected products talk to their healthcare provider about changing to a newer model insulin pump with increased cybersecurity protection. Patients outside the U.S. will receive a notification letter with instructions based on the country where they live.
Medtronic recommends all patients take the cybersecurity precautions indicated below.
CYBERSECURITY PRECAUTIONS RECOMMENDED FOR ALL PATIENTS:
* Maintain tight physical control of the pump and devices connected to the pump * Do not share pump serial number * Be attentive to pump notifications, alarms, and alerts * Immediately cancel any unintended boluses (a single dose of insulin administered all at once) * Do not connect to any third-party devices or use any software not authorized by Medtronic * Disconnect CareLink USB devices from computers when not being used to download data from the pump * Monitor blood glucose levels closely and act as appropriate * Get medical help immediately when experiencing symptoms of severe hypoglycemia or diabetic ketoacidosis, or suspect an insulin pump settings, or insulin delivery have changed unexpectedly
Medtronic has released additional patient-focused information, at the following location:
https://www.medtronic.com/security
References (5)
- http://www.securityfocus.com/bid/108926 vdb-entryThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2678 Advisory
- https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed-508-paradigm.html
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-178-01
- https://www.us-cert.gov/ics/advisories/icsma-19-178-01 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108926 | vdb-entryThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2678 | Advisory | |
| https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed-508-paradigm.html | ||
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-178-01 | ||
| https://www.us-cert.gov/ics/advisories/icsma-19-178-01 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.