ZeroHour

CVE-2018-14781

CVSS 3.1
5.3 medium
EPSS
<1%p51
Published
()
Modified
Description

Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.

Vendors
medtronicdiabetes
Products
508 minimed insulin pump firmware, 522 paradigm real-time firmware, 722 paradigm real-time firmware, 523 paradigm revel firmware, 723 paradigm revel firmware, 523k paradigm revel firmware, 723k paradigm revel firmware, 551 minimed 530g firmware, 751 minimed 530g firmware
Weakness
CWE-294, CWE-287
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.