{ "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "2090 CareLink Programmer", "vendor": "Medtronic", "versions": [ { "status": "affected", "version": "All versions" } ] }, { "defaultStatus": "unaffected", "product": "29901 Encore Programmer", "vendor": "Medtronic", "versions": [ { "status": "affected", "version": "All versions" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Billy Rios and Jonathan Butts of Whitescope LLC identified these vulnerabilities and reported them to CISA." } ], "datePublic": "2018-06-29T06:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Medtronic 2090 CareLink Programmer \n\nuses a per-product username and password that is stored in a recoverable format. \n\n\n\n
" } ], "value": "Medtronic 2090 CareLink Programmer \n\nuses a per-product username and password that is stored in a recoverable format." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 4.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-257", "description": "CWE-257", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert", "dateUpdated": "2025-05-22T17:40:34.569Z" }, "references": [ { "url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/carelink-2090-29901.html" }, { "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-18-058-01" } ], "source": { "advisory": "ICSMA-18-058-01", "discovery": "EXTERNAL" }, "title": "Medtronic 2090 Carelink Programmer Storing Passwords in a Recoverable Format", "workarounds": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Medtronic has assessed the vulnerabilities and determined that no new potential safety risks were identified. In order to enhance system security, Medtronic has added periodic integrity checks for files associated with the software deployment network. Additionally, Medtronic has developed server-side security changes that further enhance security. Medtronic reports that they will not be issuing a product update; however, Medtronic has identified compensating controls within this advisory to reduce the risk of exploitation and reiterates the following from the CareLink 2090 Programmer Reference Manual:
Medtronic has deployed mitigating patches to address the reported vulnerabilities. Medtronic has also stated that they have increased security controls associated with these vulnerabilities. As a result of the available mitigating patches, Medtronic has re-enabled the network-based software update mechanism.
Medtronic has stated that the patch for affected products can be obtained by contacting Medtronic Technical Services at 800‑638‑1991.
After additional review and risk evaluation of the affected products, Medtronic has disabled the network-based software update mechanism, including both the VPN and the HTTP subservices, as an immediate security mitigation. Users should not attempt to update the affected products over the network as this update mechanism is vulnerable to the attack described in section 4.2.3. Medtronic will continue to implement and deploy increased security protections and mitigations to address the vulnerabilities in this advisory.
Users should still obtain and apply updates via controlled USB dongles and should contact their Medtronic representative for more information.
Medtronic recommends that affected products continue to be used for their intended purpose in the previously described manner.
Medtronic has released a security bulletin for the 2090 CareLink Programmer.