The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104213 | |
https://global.medtronic.com/xg-en/product-security/security-bulletins/nvision.html | |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01 | Third Party Advisory US Government Resource |
https://www.medtronic.com/security | Vendor Advisory |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-137-01 | Third Party Advisory US Government Resource |
https://www.medtronic.com/security | Vendor Advisory |
Configurations
History
27 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 6.3 |
Summary | (en) The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer. |
Information
Published : 2018-07-13 19:29
Updated : 2025-06-27 17:15
NVD link : CVE-2018-10631
Mitre link : CVE-2018-10631
CVE.ORG link : CVE-2018-10631
JSON object : View
Products Affected
medtronic
- n\'vision_8870
- n\'vision_8840
- n\'vision_8840_firmware
- n\'vision_8870_firmware