CVE-2018-10626
Summary
| CVE | CVE-2018-10626 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-10 18:29:00 UTC |
| Updated | 2019-10-09 23:32:00 UTC |
| Description | A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Medtronic | Mycarelink 24950 Patient Monitor | - | All | All | All |
| Hardware | Medtronic | Mycarelink 24950 Patient Monitor | - | All | All | All |
| Operating System | Medtronic | Mycarelink 24950 Patient Monitor Firmware | - | All | All | All |
| Operating System | Medtronic | Mycarelink 24950 Patient Monitor Firmware | - | All | All | All |
| Hardware | Medtronic | Mycarelink 24952 Patient Monitor | - | All | All | All |
| Hardware | Medtronic | Mycarelink 24952 Patient Monitor | - | All | All | All |
| Operating System | Medtronic | Mycarelink 24952 Patient Monitor Firmware | - | All | All | All |
| Operating System | Medtronic | Mycarelink 24952 Patient Monitor Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Medtronic MyCareLink Patient Monitor Security Bypass and Information Disclosure Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Medtronic MyCareLink 24950 Patient Monitor | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.