338
VMScore

CVE-2018-10626

Published: 10/08/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.8 | Impact Score: 4.9 | Exploitability Score: 4.4
CVSS v3 Base Score: 4.4 | Impact Score: 2.7 | Exploitability Score: 1.3
VMScore: 338
Vector: AV:A/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

A vulnerability exists in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

medtronic mycarelink_24952_patient_monitor_firmware -

medtronic mycarelink_24950_patient_monitor_firmware -