02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: icscertMedtronic MyCareLink Smart Improper Authentication
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.79% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 53.5% of scored records. A rank, not a probability.
- NVD base score
- 8.8 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2020-12-14 19:18Z5 YR AGO
- Last updated
- 2025-05-22 19:34Z1 YR AGO
- Reserved
- 2020-09-04
- Assigning CNA
- icscert
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.0)
- CNA CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Weaknesses
- CWE-287Improper AuthenticationClass
- Data version
- 5.1
- Document digest
- 903cde90861a16fcce6e7a301e068cf52213802a139d365897f34b35d7a4adb1
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
SRC: CNA
A firmware update to eliminates these vulnerabilities has been developed by Medtronic and is available by updating the MyCareLink Smartapp via the associated mobile application store. Upgrading to the latest v5.2 mobile application version will ensure the Patient Reader is also updated on next use. The user’s smart phone must be updated to the following operating system version for the patches to be applied: iOS 10 and above; Android 6.0 and above.
Medtronic has released additional patient focused information https://www.medtronic.com/security :
https://www.medtronic.com/xg-en/product-security/security-bulletins.html https://www.medtronic.com/xg-en/product-security/security-bulletins.html