Security bulletins
MiniMed™ 600 series pump system communication issue
Get information about a communication issue in our MiniMed™ 600 series pump system and steps to mitigate the risks.
September 20, 2022
The MiniMed™ 600 series pump system consists of components such as the pump, continuous glucose monitoring (CGM) transmitter, blood glucose meter and CareLink™ USB device that communicate wirelessly. Medtronic has recently identified a potential issue through internal testing whereby, under specific circumstances, the communication between the components of the pump system could be compromised through unauthorized access.
For unauthorized access to occur, a nearby person other than the patient or their care partner would need to gain access to the pump at the same time that the pump is being paired with other system components. This cannot be done over the internet.
Medtronic has no evidence to date that such an issue has occurred. However, in the unlikely event that unauthorized access would be successful, the access could be used to deliver too much or too little insulin through delivery of an unintended insulin bolus or because insulin delivery is slowed or stopped. Too much insulin could result in hypoglycemia (low blood sugar) which can potentially lead to seizure, coma or death. Too little insulin could result in hyperglycemia (high blood sugar) which can potentially lead to diabetic ketoacidosis.
Medtronic recommends all patients take the actions and precautions listed below.
Actions recommended for all patients:
Precautions recommended for all patients:
Medtronic has additional general security information, at the following location:
https://www.medtronic.com/security
The best step you can take now to eliminate your individual risk of unintended delivery of insulin is to permanently turn off the Remote Bolus feature on your pump. We will continue to actively monitor the situation and are committed to sharing relevant information or actions with you in the future.
We understand this impacts your experience and are here to support you. If you have further questions, please call the Medtronic 24-Hour Technical Support line at 1-800-646-4633, option 1.
How to turn off remote bolus settings?
Follow these steps to turn off the Remote Bolus feature:
MiniMed™ 670G insulin pump (MMT-1780, MMT-1781, MMT-1782)
Note: The Remote Bolus feature is not available when in SmartGuard™ Auto Mode
View larger image
The Remote Bolus screen appears
MiniMed™ 620G (MMT-1710), MiniMed™ 630G (MMT-1714, MMT-1715), and MiniMed™ 640G (MMT-1711, MMT-1712)
Note: Remote Bolus default setting is "ON".
View larger image
The Remote Bolus screen appears
Additional technical details
The vulnerability associated with the Remote Bolus feature has a CVSS 3.1 score of 4.8. The CVE number is CVE-2022-32537.