← Back to home
ICSMA-18-058-01  ·  Published 2020-01-30  ·  View on CISA ICS-CERT ↗

Medtronic 2090 Carelink Programmer Vulnerabilities (Update C)

CVSS 7.1 HIGH

Risk Summary

Successful exploitation of these vulnerabilities may allow an attacker with physical access to a 2090 Programmer to obtain per-product credentials to the software deployment network. These credentials grant access to the software deployment network, but access is limited to read-only versions of device software applications.

Remediations

  • Medtronic has assessed the vulnerabilities and determined that no new potential safety risks were identified. In order to enhance system security, Medtronic has added periodic integrity checks for files associated with the software deployment network. Additionally, Medtronic has developed server-side security changes that further enhance security. Medtronic reports that they will not be issuing a product update; however, Medtronic has identified compensating controls within this advisory to reduce the risk of exploitation and reiterates the following from the CareLink 2090 Programmer Reference Manual:
  • Medtronic has deployed mitigating patches to address the reported vulnerabilities. Medtronic has also stated that they have increased security controls associated with these vulnerabilities. As a result of the available mitigating patches, Medtronic has re-enabled the network-based software update mechanism.
  • Medtronic has stated that the patch for affected products can be obtained by contacting Medtronic Technical Services at 800 -638 -1991.
  • After additional review and risk evaluation of the affected products, Medtronic has disabled the network-based software update mechanism, including both the VPN and the HTTP subservices, as an immediate security mitigation. Users should not attempt to update the affected products over the network as this update mechanism is vulnerable to the attack described in section 4.2.3. Medtronic will continue to implement and deploy increased security protections and mitigations to address the vulnerabilities in this advisory.
  • Users should still obtain and apply updates via controlled USB dongles and should contact their Medtronic representative for more information.
  • Medtronic recommends that affected products continue to be used for their intended purpose in the previously described manner. Medtronic has released a security bulletin for the 2090 CareLink Programmer.

Affected Vendors

Medtronic

Affected Products (2)

Medtronic · 29901 Encore Programmer vers:all/*
Medtronic · 2090 CareLink Programmer vers:all/*

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more