CVE-2018-10626

Published Aug 10, 2018

Last updated 5 years ago

Overview

Description
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.
Source
ics-cert@hq.dhs.gov
NVD status
Modified

Risk scores

CVSS 3.0

Type
Primary
Base score
4.4
Impact score
2.7
Exploitability score
1.3
Vector string
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
3.8
Impact score
4.9
Exploitability score
4.4
Vector string
AV:A/AC:M/Au:S/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-345
ics-cert@hq.dhs.gov
CWE-345

Social media

Hype score
Not currently trending

Configurations