Skip to main content

Medtronic CareLink Programmer Vulnerabilities

Medtronic has released a security advisory to address three vulnerabilities in their Carelink 2090 cardiac device programmer. A local attacker could exploit these vulnerabilities to alter passwords or data sent from the programmer to devices.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Medtronic has released a security advisory to address three vulnerabilities in their Carelink 2090 cardiac device programmer. A local attacker could exploit these vulnerabilities to alter passwords or data sent from the programmer to devices.

Threat details


Threat updates

Date Update
15 Oct 2018

Medtronic have announced that both CareLink 2090 and CareLink Encore 29901 will be removed from their software distribution network. As such they will no longer be able to receive over-the-air updates. Organisations that require updates will need to contact Medtronic directly, who will send a technician to install updates securely.


Remediation advice

Medtronic have stated there is no update able to sufficiently address these vulnerabilities. They suggest users follow the compensating measures provided in the CareLink 2090 reference manual to protect themselves.

Remediation steps

Type Step

Update  

Medtronic have announced that both CareLink 2090 and CareLink Encore 29901 will be removed from their software distribution network. As such they will no longer be able to receive over-the-air updates. Organisations that require updates will need to contact Medtronic directly, who will send a technician to install updates securely.



Last edited: 17 February 2020 12:48 pm