Telemetry Protocol Weakness in Medtronic MyCareLink and CareLink Products
CVE-2019-6540

6.5MEDIUM

What is CVE-2019-6540?

The Medtronic MyCareLink Monitor and several CareLink products are vulnerable due to a lack of encryption in their telemetry protocol. This security gap allows an attacker with nearby access to intercept sensitive data during communication, which can pose serious risks to patient privacy and safety. Devices affected include various models of the MyCareLink Monitor, CareLink Monitors, and multiple CRT-D and ICD devices from Medtronic, highlighting the urgency of addressing secure communication protocols.

Affected Version(s)

Amplia CRT-D All versions

Brava CRT-D All versions

CareLink 2090 Programmer All versions

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-6540 : Telemetry Protocol Weakness in Medtronic MyCareLink and CareLink Products