Medtronic Conexus Radio Frequency Telemetry Protocol Improper Access Control
Published Mar 25, 2019
9.3
CRITICALCVSS 3.1
EPSS 0.90%
Description
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement authentication or authorization. An attacker with adjacent short-range access to an affected product, in situations where the product’s radio is turned on, can inject, replay, modify, and/or intercept data within the telemetry communication. This communication protocol provides the ability to read and write memory values to affected implanted cardiac devices; therefore, an attacker could exploit this communication protocol to change memory in the implanted cardiac device.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version 2490CStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version 24950StatusaffectedConstraints-
- Version 24952StatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Medtronic | Amplia CRT-D | unaffected |
| |||||||||
| Medtronic | Brava CRT-D | unaffected |
| |||||||||
| Medtronic | CareLink 2090 Programmer | unaffected |
| |||||||||
| Medtronic | CareLink Monitor | unaffected |
| |||||||||
| Medtronic | Claria CRT-D | unaffected |
| |||||||||
| Medtronic | Compia CRT-D | unaffected |
| |||||||||
| Medtronic | Concerto CRT-D | unaffected |
| |||||||||
| Medtronic | Concerto II CRT-D | unaffected |
| |||||||||
| Medtronic | Conexus Radio Frequency Telemetry Protocol | unaffected |
| |||||||||
| Medtronic | Consulta CRT-D | unaffected |
| |||||||||
| Medtronic | Evera ICD | unaffected |
| |||||||||
| Medtronic | Maximo II CRT-D | unaffected |
| |||||||||
| Medtronic | Maximo II ICD | unaffected |
| |||||||||
| Medtronic | Mirro ICD | unaffected |
| |||||||||
| Medtronic | Mirro MRI ICD | unaffected |
| |||||||||
| Medtronic | MyCareLink Monitor | unaffected |
| |||||||||
| Medtronic | Nayamed ND ICD | unaffected |
| |||||||||
| Medtronic | Primo ICD | unaffected |
| |||||||||
| Medtronic | Protecta ICD, Protecta CRT-D | unaffected |
| |||||||||
| Medtronic | Secura ICD | unaffected |
| |||||||||
| Medtronic | Virtuoso ICD | unaffected |
| |||||||||
| Medtronic | Virtuoso II ICD | unaffected |
| |||||||||
| Medtronic | Visia AF ICD | unaffected |
| |||||||||
| Medtronic | Viva CRT-D | unaffected |
|
Configuration 1
- 24950
- 24952
Running on/with
- n/a
Configuration 2
- 2490c
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Configuration 11
Running on/with
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Running on/with
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Running on/with
- n/a
Configuration 18
- n/a
Running on/with
- n/a
Configuration 19
- n/a
Running on/with
- n/a
Configuration 20
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Medtronic has developed mitigating patches for a subset of the affected implanted cardiac device models. These patches are installed during regular office visits. Medtronic has stated that patches for additional impacted models are being developed by Medtronic and will be deployed through future updates. Patches are currently available for the following affected models:
* Protecta CRT-D and implantable cardioverter defibrillators (ICDs), all models
* Amplia MRI CRT-D, all models (patch available in U.S. only) * Claria MRI CRT-D, all models (patch available in U.S. only) * Compia MRI CRT-D, all models (patch available in U.S. only) * Visia AF MRI ICD, all models * Visia AF ICD, all models * Brava CRT-D, all models * Evera MRI ICD, all models * Evera ICD, all models * Mirro MRI ICD, all models * Primo MRI ICD, all models * Viva CRT-D, all models
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (CVE.org) ▾
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:A/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00895) | 58.15th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.90% (0.00895) | 57.99th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.06% (0.00060) | 26.15th | v3 (v2023.03.01) |
| May 31, 2024 | 0.06% (0.00060) | 25.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00060) | 23.39th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.40% (0.01404) | 49.02th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v1 |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Jan 5, 2022 | 0.62% (0.00624) | 46.35th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (2)
- http://www.securityfocus.com/bid/107544 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-080-01 x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107544 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://ics-cert.us-cert.gov/advisories/ICSMA-19-080-01 | x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.