5.3
CVE-2018-14781
- EPSS 0.15%
- Veröffentlicht 13.08.2018 21:48:01
- Zuletzt bearbeitet 22.05.2025 17:15:22
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Medtronicdiabetes ≫ 522 Paradigm Real-time Firmware Version-
Medtronicdiabetes ≫ 722 Paradigm Real-time Firmware Version-
Medtronicdiabetes ≫ 523 Paradigm Revel Firmware Version-
Medtronicdiabetes ≫ 723 Paradigm Revel Firmware Version-
Medtronicdiabetes ≫ 523k Paradigm Revel Firmware Version-
Medtronicdiabetes ≫ 723k Paradigm Revel Firmware Version-
Medtronicdiabetes ≫ 551 Minimed 530g Firmware Version-
Medtronicdiabetes ≫ 751 Minimed 530g Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.349 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 2.9 | 5.5 | 2.9 |
AV:A/AC:M/Au:N/C:N/I:P/A:N
|
| ics-cert@hq.dhs.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).