CVE-2019-6540
Published: Mar 26, 2019
Modified: May 22, 2025
CVSS v3.1
6.5
Description
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.
| Vendor | Product | Versions |
|---|---|---|
Medtronic | Conexus Radio Frequency Telemetry Protocol | affected All versions |
Medtronic | MyCareLink Monitor | affected 24950affected 24952 |
Medtronic | CareLink Monitor | affected 2490C |
Medtronic | CareLink 2090 Programmer | affected All versions |
Medtronic | Amplia CRT-D | affected All versions |
Medtronic | Claria CRT-D | affected All versions |
Medtronic | Compia CRT-D | affected All versions |
Medtronic | Concerto CRT-D | affected All versions |
Medtronic | Concerto II CRT-D | affected All versions |
Medtronic | Consulta CRT-D | affected All versions |
Medtronic | Evera ICD | affected All versions |
Medtronic | Maximo II CRT-D | affected All versions |
Medtronic | Maximo II ICD | affected All versions |
Medtronic | Mirro ICD | affected All versions |
Medtronic | Nayamed ND ICD | affected All versions |
Medtronic | Primo ICD | affected All versions |
Medtronic | Protecta ICD, Protecta CRT-D | affected All versions |
Medtronic | Secura ICD | affected All versions |
Medtronic | Virtuoso ICD | affected All versions |
Medtronic | Virtuoso II ICD | affected All versions |
Medtronic | Visia AF ICD | affected All versions |
Medtronic | Viva CRT-D | affected All versions |
Medtronic | Brava CRT-D | affected All versions |
Medtronic | Mirro MRI ICD | affected All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now