Lucene search

K
cve[email protected]CVE-2019-6540
HistoryMar 26, 2019 - 6:29 p.m.

CVE-2019-6540

2019-03-2618:29:01
CWE-319
web.nvd.nist.gov
39
cve-2019-6540
conexus telemetry protocol
medtronic
encryption
vulnerability
nvd
adjacent short-range access

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.

Affected configurations

NVD
Node
medtronicmycarelink_monitor_24950_firmwareMatch-
AND
medtronicmycarelink_monitor_24950Match-
Node
medtronicmycarelink_monitor_24952_firmwareMatch-
AND
medtronicmycarelink_monitor_24952Match-
Node
medtroniccarelink_monitor_2490c_firmwareMatch-
AND
medtroniccarelink_monitor_2490cMatch-
Node
medtroniccarelink_2090_firmwareMatch-
AND
medtroniccarelink_2090Match-
Node
medtronicamplia_crt-d_firmwareMatch-
AND
medtronicamplia_crt-dMatch-
Node
medtronicclaria_crt-d_firmwareMatch-
AND
medtronicclaria_crt-dMatch-
Node
medtroniccompia_crt-d_firmwareMatch-
AND
medtroniccompia_crt-dMatch-
Node
medtronicconcerto_crt-d_firmwareMatch-
AND
medtronicconcerto_crt-dMatch-
Node
medtronicconcerto_ii_crt-d_firmwareMatch-
AND
medtronicconcerto_ii_crt-dMatch-
Node
medtronicconsulta_crt-d_firmwareMatch-
AND
medtronicconsulta_crt-dMatch-
Node
medtronicevera_icd_firmwareMatch-
AND
medtronicevera_icdMatch-
Node
medtronicmaximo_ii_crt-d_firmwareMatch-
AND
medtronicmaximo_ii_crt-dMatch-
Node
medtronicmaximo_ii_icd_firmwareMatch-
AND
medtronicmaximo_ii_icdMatch-
Node
medtronicmirro_icd_firmwareMatch-
AND
medtronicmirro_icdMatch-
Node
medtronicnayamed_nd_icd_firmwareMatch-
AND
medtronicnayamed_nd_icdMatch-
Node
medtronicprimo_icd_firmwareMatch-
AND
medtronicprimo_icdMatch-
Node
medtronicprotecta_icd_firmwareMatch-
AND
medtronicprotecta_icdMatch-
Node
medtronicprotecta_crt-d_firmwareMatch-
AND
medtronicprotecta_crt-dMatch-
Node
medtronicsecura_icd_firmwareMatch-
AND
medtronicsecura_icdMatch-
Node
medtronicvirtuoso_icd_firmwareMatch-
AND
medtronicvirtuoso_icdMatch-
Node
medtronicvirtuoso_ii_icd_firmwareMatch-
AND
medtronicvirtuoso_ii_icdMatch-
Node
medtronicvisia_af_icd_firmwareMatch-
AND
medtronicvisia_af_icdMatch-
Node
medtronicviva_crt-d_firmwareMatch-
AND
medtronicviva_crt-dMatch-

CNA Affected

[
  {
    "product": "Conexus Radio Frequency Telemetry Protocol",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "MyCareLink Monitor",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "24950"
      },
      {
        "status": "affected",
        "version": "24952"
      }
    ]
  },
  {
    "product": "CareLink Monitor",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "2490C"
      }
    ]
  },
  {
    "product": "CareLink 2090 Programmer",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Amplia CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Claria CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Compia CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Concerto CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Concerto II CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Consulta CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Evera ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Maximo II CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Maximo II ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Mirro ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Nayamed ND ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Primo ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Protecta ICD, Protecta CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Secura ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Virtuoso ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Virtuoso II ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Visia AF ICD",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Viva CRT-D",
    "vendor": "Medtronic",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Related for CVE-2019-6540