Medtronic CareLink Programmer Vulnerabilities
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
For further information
Threat updates
| Date | Update |
|---|---|
| 15 Oct 2018 |
Medtronic have announced that both CareLink 2090 and CareLink Encore 29901 will be removed from their software distribution network. As such they will no longer be able to receive over-the-air updates. Organisations that require updates will need to contact Medtronic directly, who will send a technician to install updates securely. |
Remediation advice
Medtronic have stated there is no update able to sufficiently address these vulnerabilities. They suggest users follow the compensating measures provided in the CareLink 2090 reference manual to protect themselves.Remediation steps
| Type | Step |
|---|---|
|
Update Medtronic have announced that both CareLink 2090 and CareLink Encore 29901 will be removed from their software distribution network. As such they will no longer be able to receive over-the-air updates. Organisations that require updates will need to contact Medtronic directly, who will send a technician to install updates securely. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:48 pm