Showing posts with label Peter Morgan. Show all posts
Showing posts with label Peter Morgan. Show all posts

Thursday, March 21, 2019

1 Advisory Published – 03-21-19


Today the DHS NCCIC-ICS published a medical device security advisory for products from Medtronic.

The advisory describes two vulnerabilities in Medtronic MyCareLink Monitor, CareLink Monitor, CareLink 2090 Programmer, and specific Medtronic implanted cardiac devices. The vulnerabilities were reported by Peter Morgan of Clever Security; Dave Singelée and Bart Preneel of KU Leuven; Eduard Marin formerly of KU Leuven, currently with University of Birmingham; Flavio D. Garcia; Tom Chothia of the University of Birmingham; and Rik Willems of University Hospital Gasthuisberg Leuven. Medtronic has provided generic mitigation measures pending development of appropriate updates.

The two reported vulnerabilities are:

• Improper access control - CVE-2019-6538; and
Clear-text transmission of sensitive information - CVE-2019-6540

NCCIC-ICS reports that a relatively low-skille attacker with adjacent access could exploit these vulnerabilities to  allow an attacker with adjacent short-range access to one of the affected products to interfere with, generate, modify, or intercept the radio frequency (RF) communication of the Medtronic proprietary Conexus telemetry system, potentially impacting product functionality and/or allowing access to transmitted sensitive data.

NOTE: The Food and Drug Administration has published a separate advisory for these vulnerabilities.

Thursday, June 28, 2018

ICS-CERT Publishes 1 Advisory and 1 Update for Medtronic Products


Today the DHS ICS-CERT published a medical device security advisory for products from Medtronic. They also updated a previously published medical device security advisory for products from the same company.

Medtronic Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Peter Morgan of Clever Security. Medtonic will be installing an automatic update to mitigate the vulnerabilities. There is no indication that Morgan has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of hard-coded password - CVE-2018-8870; and
Exposed dangerous method or function - CVE-2018-8868

The Medtronic advisory makes a very important point about these vulnerabilities in particular that may include an important lesson to learn for all medical devices:

“Medtronic encourages patients to only use home monitors obtained directly from Medtronic or their clinician. Patients should not use a pre-owned MyCareLink Patient Monitor or one that is purchased secondhand or online. Monitors obtained through unofficial means are at an increased risk for exploitation associated with the vulnerabilities identified.”

ICS-CERT reports that an uncharacterized attacker with physical access to the monitor can exploit these vulnerabilities to allow privileged access to the monitor’s operating system.

Medtronic Update


This update provides new information on an advisory that was originally published on February 27th, 2018. The update includes:

• A change in format of the advisory;
• New information in the ‘Risk Evaluation’ section (formerly the ‘Impact’ section);
• Removal of the second and third paragraphs from the old ‘Impact’ section;
• Addition of a new vulnerability (Improper restriction of communication channel to intended endpoints - CVE-2018-10596); and
• Addition of a new work around (disconnecting the programmer from the network).

The revised Medtronic advisory contains some information that does not entirely match up with the new information in ICS-CERT update. They note, for instance that: “After issuing this advisory on Feb. 27, 2018, Medtronic was made aware of additional vulnerabilities [emphasis added] in the CareLink 2090 Programmer and its accompanying software deployment network.” Since Medtronic does not name the ‘vulnerabilities’ it is possible that they have been lumped into the single vulnerability listed in the ICS-CERT report.

 
/* Use this with templates/template-twocol.html */