CVE-2019-10964

HIGHCVSS 7.1/10EPSS 1.16%

Last modified

CVE-2019-10964 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. EPSS estimates a 1.16% chance of exploitation in the next 30 days.

Description

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

Metrics

CVSS 3.1
7.1/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H

EPSS Probability
1.16%

63.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MedtronicMinimed 508 FirmwareAll versions
MedtronicMinimed Paradigm 511 FirmwareAll versions
MedtronicMinimed Paradigm 512 FirmwareAll versions
MedtronicMinimed Paradigm 712 FirmwareAll versions
MedtronicMinimed Paradigm 712e FirmwareAll versions
MedtronicMinimed Paradigm 515 FirmwareAll versions
MedtronicMinimed Paradigm 715 FirmwareAll versions
MedtronicMinimed Paradigm 522 FirmwareAll versions
MedtronicMinimed Paradigm 722 FirmwareAll versions
MedtronicMinimed Paradigm 522k FirmwareAll versions
MedtronicMinimed Paradigm 722k FirmwareAll versions
MedtronicMinimed Paradigm 523 Firmware<= 2.4a
MedtronicMinimed Paradigm 723 Firmware<= 2.4a
MedtronicMinimed Paradigm 523k Firmware<= 2.4a
MedtronicMinimed Paradigm 723k Firmware<= 2.4a
MedtronicMinimed Paradigm Veo 554 Firmware<= 2.6a
MedtronicMinimed Paradigm Veo 754 Firmware<= 2.6a
MedtronicMinimed Paradigm Veo 554cm Firmware<= 2.7a
MedtronicMinimed Paradigm Veo 754cm FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10964?
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
How severe is CVE-2019-10964?
CVE-2019-10964 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 1.16% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10964?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10964?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST