CVE-2018-8868
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can exploit other vulnerabilities to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.
Published:Jul 2, 2018
Last Modified:May 22, 2025
EPS:Jul 2, 2018
EPSS Score:0.00091
CVSS Score:6.2
Affected Products
Vendor
Product
Action
Vendor
Medtronic
Product
24950 Mycarelink Monitor
Medtronic
24950 Mycarelink Monitor
Vendor
Medtronic
Product
24950 Mycarelink Monitor Firmware
Medtronic
24950 Mycarelink Monitor Firmware
Vendor
Medtronic
Product
24952 Mycarelink Monitor
Medtronic
24952 Mycarelink Monitor
Vendor
Medtronic
Product
24952 Mycarelink Monitor Firmware
Medtronic
24952 Mycarelink Monitor Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
