CPATH-2026-0035 · Medical IoT

Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices)

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsDevice-control safety + Data privacy

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Unauthenticated memory and setting changes can alter pacemaker or defibrillator therapy and create a severe wrong-therapy consequence.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The implant must be in its short-range Conexus listening state, placing the attacker nearby with suitable radio equipment.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    An unauthenticated radio session crosses into implant memory and settings and then into delivered cardiac therapy.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Unauthenticated memory and setting changes can alter pacemaker or defibrillator therapy and create a severe wrong-therapy consequence.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Unauthenticated memory and setting changes can alter pacemaker or defibrillator therapy and create a severe wrong-therapy consequence.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Legacy implants may need model-wide mitigations, clinical follow-up, or replacement because a simple remote patch is not always available.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The implant must be in its short-range Conexus listening state, placing the attacker nearby with suitable radio equipment.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Researchers demonstrated the protocol workflow, but it requires specialist radio equipment and knowledge of the implant telemetry format.

Source-backedNVD
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Unauthenticated memory and setting changes can alter pacemaker or defibrillator therapy and create a severe wrong-therapy consequence.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The same session exposes patient health, device memory, therapy settings, and operational state.

Model inference
AuthorityAT 3
Administrative or command authority

The protocol grants command and configuration access to exposed implant functions, but not a Medtronic firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

An unauthenticated radio session crosses into implant memory and settings and then into delivered cardiac therapy.

Model inference
Reuse scaleSR 3
Portable product-class technique

The protocol weakness and research technique are portable across affected Conexus device families.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each implant must be approached within radio range while listening; there is no remote fleet execution channel.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Legacy implants may need model-wide mitigations, clinical follow-up, or replacement because a simple remote patch is not always available.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Partially mitigated
Partial mitigation leaves residual exposure

Mitigation reduces the path, but rollout coverage or remaining exposed devices is not independently verified by this registry.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthenticated memory and setting changes can alter pacemaker or defibrillator therapy and create a severe wrong-therapy consequence.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:4/EV:2/LS:PARTIALLY_MITIGATEDRead the scoring method →

Privacy · Co-dominant path

Data privacy

Unencrypted telemetry exposes patient health information, device state, and treatment settings and can be replayed or modified.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker must be near an implant while its short-range Conexus telemetry channel is listening.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The radio channel crosses the implant boundary and delivers sensitive clinical and device state to an unauthorized observer.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Unencrypted telemetry exposes patient health information, device state, and treatment settings and can be replayed or modified.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Unencrypted telemetry exposes patient health information, device state, and treatment settings and can be replayed or modified.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Protocol-level mitigation must cover the affected product family, while some legacy implants cannot receive an ordinary software update.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker must be near an implant while its short-range Conexus telemetry channel is listening.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Intercepting or modifying the unencrypted protocol requires the same specialist radio setup demonstrated by researchers.

Source-backedNVD
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

This path concerns telemetry confidentiality and integrity; direct therapy manipulation is assessed in the separate safety path.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Unencrypted telemetry exposes patient health information, device state, and treatment settings and can be replayed or modified.

Model inference
AuthorityAT 2
Bounded function authority

Observation and manipulation are bounded to the active telemetry session rather than implant firmware administration.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The radio channel crosses the implant boundary and delivers sensitive clinical and device state to an unauthorized observer.

Model inference
Reuse scaleSR 3
Portable product-class technique

The protocol analysis can be reused across affected Conexus devices without learning a unique cryptographic key.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Every collection attempt remains limited to one nearby implant in a listening state.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Protocol-level mitigation must cover the affected product family, while some legacy implants cannot receive an ordinary software update.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Partially mitigated
Partial mitigation leaves residual exposure

Mitigation reduces the path, but rollout coverage or remaining exposed devices is not independently verified by this registry.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unencrypted telemetry exposes patient health information, device state, and treatment settings and can be replayed or modified.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:2/DP:3/AT:2/CH:2/SR:3/SX:2/OR:4/EV:2/LS:PARTIALLY_MITIGATEDRead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipDifferent consequence axis
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.3 CRITICALCISA/ICS-CERT via NVD (CVE-2019-6538)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
v3.1 · 6.5 MEDIUMNVD (CVE-2019-6538)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
v3.1 · 6.5 MEDIUMCISA/ICS-CERT via NVD / NVD (CVE-2019-6540)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:4/EV:2/LS:PARTIALLY_MITIGATED

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.

Adjacent short-range RF only, device must be in listening state (RE:2). Exploitation is advanced-but-reproducible: needs specialized RF gear and protocol knowledge; researchers demonstrated it (EC:2). The Conexus protocol allows read/write to implanted-device memory with no auth/authz, so an attacker can alter therapy/settings on an ICD/pacemaker -> credible injury/wrong therapy (PH:4, perception_feeds_action true since written state drives therapy delivery). Authority gained is effectively unauthenticated control over telemetry-exposed device functions/config, not the cryptographic root-of-trust or OTA signing root, so AT:3 not 4. Crosses RF/device/physical/safety boundaries (boundary_crossing). Data exposed is device/health/operational state (DP:3). Reuse: the protocol weakness is shared across a broad model class (portable knowledge/technique), SR:3. Execution is one-at-a-time per-device proximity, no fleet remote scaling (SX:2). Many legacy implants cannot be field-patched; mitigation partial/ongoing and recovery would require model-level updates/replacement (OR:4, recovery_needs_fleet_action). Report-backed, no in-the-wild exploitation or observed harm (EV:2, active_exploitation false). LS partially mitigated.

DATA_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:2/CH:2/SR:3/SX:2/OR:4/EV:2/LS:PARTIALLY_MITIGATED

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=ELEVATED → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.

Same adjacent-RF position with device in listening state (RE:2) and advanced-but-reproducible interception of unencrypted Conexus telemetry (EC:2). No encryption means sensitive implant/patient device and health data can be intercepted; injected/replayed/modified telemetry can falsify device data (DP:3 health/sensitive-op-state). This terminal is confidentiality/integrity of telemetry rather than therapy actuation, so physical impact is limited to measurement/data-falsification disruption without direct severe harm (PH:2); the falsified data does not by itself drive safety actuation in this path (perception_feeds_action false). Authority consequence is bounded read of session/telemetry channel (AT:2). Crosses RF/device boundaries (boundary_crossing). Knowledge/technique portable across the device class (SR:3); execution per-device proximity, not remote/fleet (SX:2). Legacy implants unpatchable so protocol-level fix needs broad updates (OR:4, recovery_needs_fleet_action). Report-backed, NVD scored C:N at protocol level but disclosure notes interception possible; no observed exploitation (EV:2, active_exploitation false).

Published baseline

  • v3.1 9.3 CRITICAL — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H — CISA/ICS-CERT via NVD (CVE-2019-6538)
  • v3.1 6.5 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N — NVD (CVE-2019-6538)
  • v3.1 6.5 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N — CISA/ICS-CERT via NVD / NVD (CVE-2019-6540)

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0035 (“Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices)”), paths.cfse.ai/CPATH-2026-0035 (published 2026-06-03).