CVE-2018-10626
4.4MEDIUMMedtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired im
Publicado: 8/10/2018Actualizado: 5/22/2025
Descripción
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.
Análisis IAImpulsado por IA
Productos Afectados
medtronicmycarelink_24952_patient_monitor_firmware
-
medtronicmycarelink_24952_patient_monitor
-
medtronicmycarelink_24950_patient_monitor_firmware
-
medtronicmycarelink_24950_patient_monitor
-
Referencias
- http://www.securityfocus.com/bid/105042Third Party AdvisoryVDB Entry
- https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-8-7-18.html
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/105042Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01Third Party AdvisoryUS Government Resource