Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality.
This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
Metrics
Affected Vendors & Products
References
History
Thu, 24 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Title | Medtronic MyCareLink Patient Monitor Empty Password Vulnerability | |
| Weaknesses | CWE-258 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Medtronic
Published: 2025-07-24T03:30:24.185Z
Updated: 2025-07-24T13:18:56.146Z
Reserved: 2025-05-06T20:01:00.625Z
Link: CVE-2025-4395
Updated: 2025-07-24T13:18:53.736Z
Status : Awaiting Analysis
Published: 2025-07-24T07:15:53.660
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-4395
No data.