CVE-2019-6538 describes a critical authentication and authorization bypass in the Conexus telemetry protocol used by various Medtronic implanted cardiac devices and monitoring systems. An attacker with adjacent short-range access can inject, replay, modify, or intercept data, potentially altering memory values in the implanted devices. This vulnerability has a CVSS score of 6.5 (Medium) due to its low attack complexity and high impact on integrity, despite requiring physical proximity. While there are no known public exploits or active exploitation, the vulnerability has garnered significant media attention and community discussion, highlighting the potential for serious consequences if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24950CPE matchmatch criteria | cpe:2.3:o:medtronic:mycarelink_monitor_firmware:24950:*:*:*:*:*:*:* | ||
24952CPE matchmatch criteria | cpe:2.3:o:medtronic:mycarelink_monitor_firmware:24952:*:*:*:*:*:*:* | ||
2490cCPE matchmatch criteria | cpe:2.3:o:medtronic:carelink_monitor_firmware:2490c:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:medtronic:carelink_2090_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:medtronic:amplia_crt-d_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.