Back

CRITICAL

Medtronic Conexus Radio Frequency Telemetry Protocol Improper Access Control

Published Mar 25, 2019

Description

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement authentication or authorization. An attacker with adjacent short-range access to an affected product, in situations where the product’s radio is turned on, can inject, replay, modify, and/or intercept data within the telemetry communication. This communication protocol provides the ability to read and write memory values to affected implanted cardiac devices; therefore, an attacker could exploit this communication protocol to change memory in the implanted cardiac device.

Affected products

Remediation

Vendor solution

Medtronic has developed mitigating patches for a subset of the affected implanted cardiac device models. These patches are installed during regular office visits. Medtronic has stated that patches for additional impacted models are being developed by Medtronic and will be deployed through future updates. Patches are currently available for the following affected models:

* Protecta CRT-D and implantable cardioverter defibrillators (ICDs), all models

* Amplia MRI CRT-D, all models (patch available in U.S. only) * Claria MRI CRT-D, all models (patch available in U.S. only) * Compia MRI CRT-D, all models (patch available in U.S. only) * Visia AF MRI ICD, all models * Visia AF ICD, all models * Brava CRT-D, all models                                             * Evera MRI ICD, all models * Evera ICD, all models * Mirro MRI ICD, all models * Primo MRI ICD, all models * Viva CRT-D, all models

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Mar 25, 2019
Updated May 22, 2025
Reserved Jan 22, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a