SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25183

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass.

HIGH 8.8EPSS 0.80%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.80% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
medtronic/mycarelink smart model 25000 firmware
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.