Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.
Workaround:
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed.html | |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-02 | third party advisory us government resource |
http://www.securityfocus.com/bid/105044 | vdb entry third party advisory |