Medtronic MyCareLink Smart 25000 contains

an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-17874 Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.
Fixes

Solution

A firmware update to eliminates these vulnerabilities has been developed by Medtronic and is available by updating the MyCareLink Smartapp via the associated mobile application store. Upgrading to the latest v5.2 mobile application version will ensure the Patient Reader is also updated on next use. The user’s smart phone must be updated to the following operating system version for the patches to be applied: iOS 10 and above; Android 6.0 and above. Medtronic has released additional patient focused information https://www.medtronic.com/security : https://www.medtronic.com/xg-en/product-security/security-bulletins.html https://www.medtronic.com/xg-en/product-security/security-bulletins.html


Workaround

In response to these vulnerabilities, Medtronic has applied additional controls for monitoring and responding to improper use of the MCL Smart Patient Reader: * Medtronic has implemented enhanced integrity validation (EIV) technology, which provides early detection and real-time mitigation of known vulnerability exploitation attempts. * Medtronic has also implemented advanced detection system technology, which enables device-level logging and monitoring of all device activity and behavior. Medtronic recommends that users take additional defensive measures to minimize risk. Specifically, users should: * Maintain good physical control over home monitors. * This includes only using home monitors in private environments such as a home, apartment, or otherwise physically controlled environment. * Use only home monitors obtained directly from your healthcare provider or a Medtronic representative. * Patients should ensure that the operating system of their mobile phone is updated to the latest version of the available Android or Apple iOS operating system. Report any concerning behavior regarding these products to your healthcare provider or a Medtronic representative.

History

Thu, 22 May 2025 19:45:00 +0000

Type Values Removed Values Added
Description Medtronic MyCareLink Smart 25000 all versions contain an authentication protocol vuln where the method used to auth between MCL Smart Patient Reader and MyCareLink Smart mobile app is vulnerable to bypass. This vuln allows attacker to use other mobile device or malicious app on smartphone to auth to the patient’s Smart Reader, fools the device into thinking its communicating with the actual smart phone application when executed in range of Bluetooth. Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.
Title Medtronic MyCareLink Smart Improper Authentication
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-05-22T19:34:29.069Z

Reserved: 2020-09-04T00:00:00

Link: CVE-2020-25183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-14T20:15:12.590

Modified: 2025-05-22T20:15:21.237

Link: CVE-2020-25183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.