CVE-2018-14781

MEDIUMCVSS 5.3/10EPSS 0.71%

Last modified

CVE-2018-14781 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.

Description

Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.71%

48.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Medtronicdiabetes508 Minimed Insulin Pump FirmwareAll versions
Medtronicdiabetes522 Paradigm Real-Time FirmwareAll versions
Medtronicdiabetes722 Paradigm Real-Time FirmwareAll versions
Medtronicdiabetes523 Paradigm Revel FirmwareAll versions
Medtronicdiabetes723 Paradigm Revel FirmwareAll versions
Medtronicdiabetes523k Paradigm Revel FirmwareAll versions
Medtronicdiabetes723k Paradigm Revel FirmwareAll versions
Medtronicdiabetes551 Minimed 530g FirmwareAll versions
Medtronicdiabetes751 Minimed 530g FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-14781?
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.
How severe is CVE-2018-14781?
CVE-2018-14781 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.71% probability of exploitation in the next 30 days.
How do I fix CVE-2018-14781?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-14781?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST