René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

728 lines
20 KiB
JSON

{
"id": "CVE-2019-6540",
"sourceIdentifier": "ics-cert@hq.dhs.gov",
"published": "2019-03-26T18:29:01.060",
"lastModified": "2021-11-03T18:57:30.320",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data."
},
{
"lang": "es",
"value": "El protocolo de telemetr\u00eda Conexus empleado en Medtronic MyCareLink Monitor, en las versiones 24950 y 24952; CareLink Monitor, en su versi\u00f3n 2490C; CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D y ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD y CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD y Viva CRT-D no implementan cifrado. Un atacante con acceso adyacente de rango corto a un producto objetivo puede escuchar las comunicaciones, incluyendo la transmisi\u00f3n de datos sensibles."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:A/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "ADJACENT_NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 3.3
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.5,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
},
{
"source": "ics-cert@hq.dhs.gov",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mycarelink_monitor_24950_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8F443021-E300-4FFF-9C57-2492ED18156A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mycarelink_monitor_24950:-:*:*:*:*:*:*:*",
"matchCriteriaId": "72727063-B325-4B3F-9EC7-84D108132310"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mycarelink_monitor_24952_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "15E9E727-AE85-4A57-A703-CC33F69B37A2"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mycarelink_monitor_24952:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B55FAA47-3C6F-4EDB-B061-09951AC4675C"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:carelink_monitor_2490c_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B6355A1D-E9CC-45E4-A287-9D53CB908BC6"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:carelink_monitor_2490c:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2F7E9489-DAFA-4115-B238-4E7CEA951DB3"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:carelink_2090_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8FE6438F-F84A-4876-B13E-4C06050EF7D4"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:carelink_2090:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CA96FB28-A2B2-4144-87F2-19D0EEB3CBB2"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:amplia_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "53F40F63-1FFD-4F1D-BB91-A0109CCE62A3"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:amplia_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E64609AE-EA44-423A-B0E1-5FBF219165C9"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:claria_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A9F3C231-C8D2-40A1-BA0D-8381208AD3B5"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:claria_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "756E8B59-2D00-4647-8DCE-A293626FFFDD"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:compia_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "832EC0E7-9AD0-42E9-9663-F9033763ADF1"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:compia_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "41A7F4D2-233C-4BF7-9054-C814CE5110DF"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:concerto_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "008FD034-1206-41DA-9537-1F4244236286"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:concerto_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "94A17D5C-5BC8-4066-8C2C-7AB6CA25B4F0"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:concerto_ii_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7FA48969-0F33-434D-B210-B18D0459316C"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:concerto_ii_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "77FD6FAE-32FD-48DD-8A95-881C9373F9EE"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:consulta_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D02CD1C6-9229-408A-8E6E-CAB394DC489A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:consulta_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F6347AAA-ACB2-4CDF-B3F5-49CA8BB17577"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:evera_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "64C40F66-1FA6-4DC6-BA87-4D7811650F81"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:evera_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "DEBB88DD-94C3-478D-8AFE-BC63BA73E94C"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:maximo_ii_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5FAFA3B0-D7F1-4C21-AEDD-5E631B0911A2"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:maximo_ii_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6DBEB243-52D7-4234-ADE6-82A512D4D32A"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:maximo_ii_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BFC24421-D3A1-48DB-9646-69B0C504F9D8"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:maximo_ii_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "70C76A8B-0478-4509-8D89-E3A4DD88666F"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mirro_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FBAA5C99-D5AA-4377-86A0-48862582F769"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mirro_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1525A59B-E8F7-43FD-8ECD-5546C4E268F6"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:nayamed_nd_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F92F9AA6-56B1-4969-AADD-0D181F1F26F5"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:nayamed_nd_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F6BA1499-CB4E-4067-984E-048CADDB5473"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:primo_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "374D02EF-E15A-4C1A-BB1B-770F3FB75EC7"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:primo_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1941334A-A540-4ED3-8DCF-9298DC18D67E"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:protecta_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3009F789-2538-4E16-AA8C-A53E86481BFB"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:protecta_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "ABC6DC8C-A2CE-42B4-8E40-34D96CE68D9A"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:protecta_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "265C5C70-FD73-4A5D-91AE-F5C1CD912369"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:protecta_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F1EDDCB8-30F5-474B-9A93-772E16F584B4"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:secura_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "348706DF-2F3D-4875-9450-218A2A4E9210"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:secura_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A82FFC9C-960C-4709-AB17-0D6C7BC0E39E"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:virtuoso_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "85BD02A6-B421-4E90-A91E-D966F3CE70A8"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:virtuoso_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "618D26D4-6690-4F17-B9F5-2CD05486EB65"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:virtuoso_ii_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F9B06688-4AF7-4354-A6AF-B335424F1D51"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:virtuoso_ii_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C2F9A58D-D3E8-4E57-93D9-A1FB1BEB65D6"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:visia_af_icd_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5D21AD86-5D91-4279-8A54-9A6E6A1B6960"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:visia_af_icd:-:*:*:*:*:*:*:*",
"matchCriteriaId": "17418686-EC2F-4FDB-88F8-2B4C60A8B48D"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:viva_crt-d_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "468772A4-BCD2-4884-A7C0-4CD49DFC6C1E"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:viva_crt-d:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7222E296-5DA5-4611-BA1C-85059D7918A0"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/107544",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Broken Link"
]
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSMA-19-080-01",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"US Government Resource",
"Third Party Advisory"
]
}
]
}