Vulnerability Details CVE-2019-6540
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 3.3
Products affected by CVE-2019-6540
-
cpe:2.3:h:medtronic:amplia_crt-d:-
-
cpe:2.3:h:medtronic:carelink_2090:-
-
cpe:2.3:h:medtronic:carelink_monitor_2490c:-
-
cpe:2.3:h:medtronic:claria_crt-d:-
-
cpe:2.3:h:medtronic:compia_crt-d:-
-
cpe:2.3:h:medtronic:concerto_crt-d:-
-
cpe:2.3:h:medtronic:concerto_ii_crt-d:-
-
cpe:2.3:h:medtronic:consulta_crt-d:-
-
cpe:2.3:h:medtronic:evera_icd:-
-
cpe:2.3:h:medtronic:maximo_ii_crt-d:-
-
cpe:2.3:h:medtronic:maximo_ii_icd:-
-
cpe:2.3:h:medtronic:mirro_icd:-
-
cpe:2.3:h:medtronic:mycarelink_monitor_24950:-
-
cpe:2.3:h:medtronic:mycarelink_monitor_24952:-
-
cpe:2.3:h:medtronic:nayamed_nd_icd:-
-
cpe:2.3:h:medtronic:primo_icd:-
-
cpe:2.3:h:medtronic:protecta_crt-d:-
-
cpe:2.3:h:medtronic:protecta_icd:-
-
cpe:2.3:h:medtronic:secura_icd:-
-
cpe:2.3:h:medtronic:virtuoso_icd:-
-
cpe:2.3:h:medtronic:virtuoso_ii_icd:-
-
cpe:2.3:h:medtronic:visia_af_icd:-
-
cpe:2.3:h:medtronic:viva_crt-d:-
-
cpe:2.3:o:medtronic:amplia_crt-d_firmware:-
-
cpe:2.3:o:medtronic:carelink_2090_firmware:-
-
cpe:2.3:o:medtronic:carelink_monitor_2490c_firmware:-
-
cpe:2.3:o:medtronic:claria_crt-d_firmware:-
-
cpe:2.3:o:medtronic:compia_crt-d_firmware:-
-
cpe:2.3:o:medtronic:concerto_crt-d_firmware:-
-
cpe:2.3:o:medtronic:concerto_ii_crt-d_firmware:-
-
cpe:2.3:o:medtronic:consulta_crt-d_firmware:-
-
cpe:2.3:o:medtronic:evera_icd_firmware:-
-
cpe:2.3:o:medtronic:maximo_ii_crt-d_firmware:-
-
cpe:2.3:o:medtronic:maximo_ii_icd_firmware:-
-
cpe:2.3:o:medtronic:mirro_icd_firmware:-
-
cpe:2.3:o:medtronic:mycarelink_monitor_24950_firmware:-
-
cpe:2.3:o:medtronic:mycarelink_monitor_24952_firmware:-
-
cpe:2.3:o:medtronic:nayamed_nd_icd_firmware:-
-
cpe:2.3:o:medtronic:primo_icd_firmware:-
-
cpe:2.3:o:medtronic:protecta_crt-d_firmware:-
-
cpe:2.3:o:medtronic:protecta_icd_firmware:-
-
cpe:2.3:o:medtronic:secura_icd_firmware:-
-
cpe:2.3:o:medtronic:virtuoso_icd_firmware:-
-
cpe:2.3:o:medtronic:virtuoso_ii_icd_firmware:-
-
cpe:2.3:o:medtronic:visia_af_icd_firmware:-
-
cpe:2.3:o:medtronic:viva_crt-d_firmware:-