6.8
/ 10
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
Basic Information
ID
CVE-2025-4397
Source
Medtronic
Published
May 7, 2026 at 15:03
Modified
May 7, 2026 at 15:45
Affected Product
Vendor
Medtronic
Product
MyCareLink Patient Monitor 24950
Affected Versions
Medtronic MyCareLink Patient Monitor 24950 0
Medtronic MyCareLink Patient Monitor 24952 0
Medtronic MyCareLink Patient Monitor 24952 0
CWE Classification
References
- www.medtronic.com /en-us/e/product-security/security-bulletins/mycarelink-patient-monitor-vulnerabilities.html
- www.cisa.gov /news-events/ics-medical-advisories/icsma-25-205-01
- www.medtronic.com /en-us/e/product-security/security-bulletins/mycarelink-8-7-18.html
- www.cisa.gov /news-events/ics-medical-advisories/icsma-18-219-01