Skip to main content

Medtronic MyCareLink Patient Monitor Vulnerabilities

Medtronic has released a security update to address two vulnerabilities in their MyCareLink patient monitors. A remote attacker could exploit these vulnerabilities to obtain device data or cause a denial- of-service condition.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Medtronic has released a security update to address two vulnerabilities in their MyCareLink patient monitors. A remote attacker could exploit these vulnerabilities to obtain device data or cause a denial- of-service condition.

Threat details

For further information


Remediation steps

Type Step
Medtronic have released server-side updates to address CVE-2018-10626 and are in the process of releasing another server-side update to address CVE-2018-10622. Users and administrators are encouraged to visit Medtronic's security pages for further information.

Last edited: 17 February 2020 12:48 pm