Medtronic MyCareLink Smart Vulnerabilities
Three vulnerabilities have been discovered in Medtronic's MyCareLink Smart patient monitors which could be exploited to control cardiac devices used by home patients.
Summary
Three vulnerabilities have been discovered in Medtronic's MyCareLink Smart patient monitors which could be exploited to control cardiac devices used by home patients.
Affected platforms
The following platforms are known to be affected:
Medtronic MyCareLink Smart 25000 patient monitor
Threat details
Introduction
Medtronic has released detail of three vulnerabilities affecting their MyCareLink (MCL) Smart 25000 patient monitors. They claim that an unauthenticated attacker within Bluetooth range could take control of connected patient devices.
Vulnerabilities
- CVE-2020-25183 - The authentication protocol used between MCL Smart patient monitors and Medtronic's MCL Smart mobile application can be bypassed. This allows an attacker to use a malicious application on the user's mobile device, or a separate mobile device, to send commands to a connected Medtronic patient device.
- CVE-2020-25187 - MCL Smart patient monitors allow authenticated users to run debug commands, resulting in a heap-based buffer overflow. This overflow can then be exploited to send command to the monitor.
- CVE-2020-27252 - MCL Smart patient monitors are vulnerable to a race condition in their update software, which could allow an attacker to upload unsigned firmware to an affected device.
Remediation advice
Medtronic has released a new firmware version (V5.2) for affected MCL Smart monitors which is available to through the MyCareLink Smartapp mobile application. Affected user and organisations are encouraged to update to this version as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 15 December 2020 3:17 pm