CVE-2018-14781

MEDIUM

Medtronic MiniMed MMT - Capture-Replay

Title source: llm
STIX 2.1

Description

Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-02
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/105044

Scores

CVSS v3 5.3
EPSS 0.0071
EPSS Percentile 48.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287 CWE-294
Status published
Products (9)
medtronicdiabetes/508_minimed_insulin_pump_firmware
medtronicdiabetes/522_paradigm_real-time_firmware
medtronicdiabetes/523_paradigm_revel_firmware
medtronicdiabetes/523k_paradigm_revel_firmware
medtronicdiabetes/551_minimed_530g_firmware
medtronicdiabetes/722_paradigm_real-time_firmware
medtronicdiabetes/723_paradigm_revel_firmware
medtronicdiabetes/723k_paradigm_revel_firmware
medtronicdiabetes/751_minimed_530g_firmware
Published Aug 13, 2018
Tracked Since Feb 18, 2026