Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.
Workaround:
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-8-7-18.html | |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/105042 | third party advisory vdb entry |