Medtronic Updates
2946Warning Date
Severity Level
Warning Number
Target Sector
9 June, 2020
● High
2020-1330
HealthCare
Description:
Medtronic has released security updates to address multiple vulnerabilities in the following products:
- MyCareLink Monitor
- Versions 24950 and 24952
- CareLink Monitor
- Version 2490C
- CareLink 2090 Programmer
- Amplia CRT-D
- all models
- Claria CRT-D
- all models
- Compia CRT-D
- all models
- Concerto CRT-D
- all models
- Concerto II CRT-D
- all models
- Consulta CRT-D
- all models
- Evera ICD
- all models
- Maximo II CRT-D and ICD
- all models
- Mirro ICD
- all models
- Nayamed ND ICD
- all models
- Primo ICD
- all models
- Protecta ICD and CRT-D
- all models
- Secura ICD
- all models
- Virtuoso ICD
- all models
- Virtuoso II ICD
- all models
- Visia AF ICD
- all models
- Viva CRT-D
- all models
- Brava CRT-D
- all models
- Mirro MRI ICD
- all models
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Improper Access Control
- Unauthorized disclosure of information
Best practice and Recommendations:
The CERT team encourages users to review Medtronic security advisory and apply the necessary updates for the following products:
- Visia AF MRI ICD
- Visia AF ICD
- Brava CRT-D
- Evera MRI ICD
- Evera ICD
- Mirro MRI ICD
- Primo MRI ICD
- Viva CRT-D
In addition, Medtronic has stated that patches for additional impacted models are being developed by Medtronic and will be deployed through future updates. For more information: