Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf7p-63p6-4m97

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

EPSS

Процентиль: 10%
0.00036
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 4.4
nvd
больше 7 лет назад

Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

CVSS3: 4.4
fstec
больше 7 лет назад

Уязвимость медицинского оборудования Medtronic MyCareLink Patient Monitor, связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю загружать произвольную информацию в сеть Medtronic CareLink

EPSS

Процентиль: 10%
0.00036
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-345