← Back to home
ICSMA-19-178-01  ·  Published 2019-06-27  ·  View on CISA ICS-CERT ↗

Medtronic MiniMed 508 and Paradigm Series Insulin Pumps

CVSS 7.1 HIGH

Risk Summary

Successful exploitation of this vulnerability may allow an attacker with adjacent access to one of the affected products to intercept, modify, or interfere with the wireless RF (radio frequency) communications to or from the product. This may allow attackers to read sensitive data, change pump settings, or control insulin delivery.

CVEs (1)

Remediations

  • Medtronic recommends U.S. patients who are currently using the affected products talk to their healthcare provider about changing to a newer model insulin pump with increased cybersecurity protection. Patients outside the U.S. will receive a notification letter with instructions based on the country where they live.
  • Medtronic recommends all patients take the cybersecurity precautions indicated below.
  • CYBERSECURITY PRECAUTIONS RECOMMENDED FOR ALL PATIENTS:
  • Medtronic has released additional patient-focused information, at the following location:
  • https://www.medtronic.com/security
  • Additionally, Medtronic will be sending a letter to all patients who are current known users of these pumps further detailing the risks and defensive measures.
  • https://www.fda.gov/MedicalDevices/DigitalHealth/ucm373213.htm

Affected Vendors

Medtronic

Affected Products (11)

Medtronic · MiniMed Paradigm 522K/722K pumps vers:all/*
Medtronic · MiniMed Paradigm 515/715 pumps vers:all/*
Medtronic · MiniMed 508 pump vers:all/*
Medtronic · MiniMed Paradigm 712E pump vers:all/*
Medtronic · MiniMed Paradigm Veo 554/754 pumps <= 2.6A
Medtronic · MiniMed Paradigm 522/722 pumps vers:all/*
Medtronic · MiniMed Paradigm Veo 554CM and 754CM models only <= 2.7A
Medtronic · MiniMed Paradigm 523K/723K pumps <= 2.4A
Medtronic · MiniMed Paradigm 523/723 pumps <= 2.4A
Medtronic · MiniMed Paradigm 511 pump vers:all/*
Medtronic · MiniMed Paradigm 512/712 pumps vers:all/*

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more