TiYunZong Vulnerability on CT900 Samsung Android Tablet SECURITY BULLETIN

November 19, 2020

Purpose

This Medtronic Security Bulletin provides product specific information concerning the TiYunZong security vulnerability on the CT900 Samsung Android tablets and how to mitigate the vulnerability. Medtronic uses these tablets to run several Medtronic Neuromodulation Clinician Programmer Applications.

To date, no cyberattack, no unauthorized access to patient data, and no harm to patients has been observed with these vulnerabilities.

Impact Summary

To date, no cyberattack, patient harm, or data compromise has been observed with these vulnerabilities.

Given that the Clinicial Programmer Applications run on the Samsung tablet, Medtronic applications may be indirectly impacted.

General Summary

Security researchers discovered potential vulnerabilities in Samsung tablets (assigned the Medtronic Model CT900) that function as the hardware platform for Clinician Programmers that interact with Medtronic neurostimulators and implantable drug infusion pumps. These programmers are used by clinicians to configure therapy device settings in a hospital or clinic. In this case, the therapies impacted treat patients with chronic pain, severe spasticity, Parkinson’s disease, essential tremor, dystonia, epilepsy and obsessive-compulsive disorder.

For the vulnerability to be exploited, a CT900 tablet user (i.e. a clinician at a hospital or clinic) must visit a malicious website using the Chrome browser application on the tablet. Once that has happened, an unauthorized individual could exploit this vulnerability to gain remote access to the tablet. This could enable an unauthorized individual to access therapy or patient information or to alter device settings remotely over the internet.

Medtronic Response

Updating the Chrome browser application to version 77 or greater completely mitigates these vulnerabilities. To update:

  • Go to the Google Play Store application
  • Search for the “Google Chrome browser” application
  • Select update to automatically update to a patched version of the Chrome application

Medtronic Field Representatives will check devices and assist Clinicians to ensure the Chrome browser application is updated in the weeks following issuance of this bulletin.

 

List of Affected Products

The CT900 Samsung Android tablets are used for running the following Medtronic applications:

Product Name Use

A610 – DBS Clinician Programmer Application

Used by clinicians for programming of Medtronic neurostimulators (external and implantable) for deep brain stimulation (DBS)

A710 – Intelis Clinician Programmer Application

Used by clinicians for programming of Medtronic neurostimulators (external and implantable) for pain therapy

A71100 – Restore Clinician Application

Used by clinicians for programming of Medtronic neurostimulators for pain therapy

A810 – SynchroMedII Clinician Programmer Application

Intended for use by clinicians in the programming of the Model 8637 SynchroMed II Programmable Pump for intrathecal applications

Patients or clinicians with questions or concerns about these devices should contact:

Technical Services: 1-800-707-0933
Or contact your Medtronic representative.