CVE-2019-10964 - CVE House
Back to Database
Status published High CVE-2019-10964

Medtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access Control

Vulnerability Description

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10964

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Based on earlier work performed by external researchers including Nathanael Paul, Jay Radcliffe, and Barnaby Jack, and from recent work performed by external researchers Billy Rios, Jonathan Butts, and Jesse Young, Medtronic performed additional variant analysis and reported this vulnerability

Affected Vendor

Affected Software

MiniMed 508 pump, MiniMed Paradigm 511 pump, MiniMed Paradigm 512/712 pumps, MiniMed Paradigm 712E pump, MiniMed Paradigm 515/715 pumps, MiniMed Paradigm 522/722 pumps, MiniMed Paradigm 522K/722K pumps, MiniMed Paradigm 523/723 pumps, MiniMed Paradigm 523K/723K pumps, MiniMed Paradigm Veo 554/754 pumps, MiniMed Paradigm Veo 554CM/754CM pumps
Vulnerable Versions:
All versions, 0

Timeline

Official Publish: June 28th, 2019
Last Modified: May 22nd, 2025
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H

Weaknesses (CWE)