{ "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "Smart Model 25000 Patient Reader", "vendor": "Medtronic", "versions": [ { "status": "affected", "version": "All versions" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Sternum, based in Tel Aviv, Israel, discovered and initially reported these vulnerabilities to Medtronic." } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Medtronic MyCareLink Smart 25000 is \n\nvulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.\n\n
A firmware update to eliminates these vulnerabilities has been developed by Medtronic and is available by updating the MyCareLink Smartapp via the associated mobile application store. Upgrading to the latest v5.2 mobile application version will ensure the Patient Reader is also updated on next use. The user’s smart phone must be updated to the following operating system version for the patches to be applied: iOS 10 and above; Android 6.0 and above.
Medtronic has released additional patient focused information:
https://www.medtronic.com/xg-en/product-security/security-bulletins.html
\n\nIn response to these vulnerabilities, Medtronic has applied additional controls for monitoring and responding to improper use of the MCL Smart Patient Reader:
Medtronic recommends that users take additional defensive measures to minimize risk. Specifically, users should:
Report any concerning behavior regarding these products to your healthcare provider or a Medtronic representative.
\n\n