Skip to main content

Medtronic MyCareLink Smart Vulnerabilities

Three vulnerabilities have been discovered in Medtronic's MyCareLink Smart patient monitors which could be exploited to control cardiac devices used by home patients.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Three vulnerabilities have been discovered in Medtronic's MyCareLink Smart patient monitors which could be exploited to control cardiac devices used by home patients.


Affected platforms

The following platforms are known to be affected:

Medtronic MyCareLink Smart 25000 patient monitor


Threat details

Introduction

Medtronic has released detail of three vulnerabilities affecting their MyCareLink (MCL) Smart 25000 patient monitors. They claim that an unauthenticated attacker within Bluetooth range could take control of connected patient devices.


Vulnerabilities

  • CVE-2020-25183 - The authentication protocol used between MCL Smart patient monitors and Medtronic's MCL Smart mobile application can be bypassed. This allows an attacker to use a malicious application on the user's mobile device, or a separate mobile device, to send commands to a connected Medtronic patient device.
  • CVE-2020-25187 - MCL Smart patient monitors allow authenticated users to run debug commands, resulting in a heap-based buffer overflow. This overflow can then be exploited to send command to the monitor.
  • CVE-2020-27252 - MCL Smart patient monitors are vulnerable to a race condition in their update software, which could allow an attacker to upload unsigned firmware to an affected device.

Remediation advice

Medtronic has released a new firmware version (V5.2) for affected MCL Smart monitors which is available to through the MyCareLink Smartapp mobile application. Affected user and organisations are encouraged to update to this version as soon as possible.



Last edited: 15 December 2020 3:17 pm