CVE-2018-14781: Medtronicdiabetes 508 Minimed Insulin Pump Firmware

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.

Affected products

Published 2018-08-13. Last modified 2026-06-17.