CVE Details
Basic Information
| Title | Medtronic MyCareLink Patient Monitor Empty Password Vulnerability |
|---|---|
| Type | cve |
| Published | 2025-07-24T03:30:24.185Z |
| Modified | 2025-07-24T03:30:24.185Z |
Product Information
| Vendor | Medtronic |
|---|---|
| Product | MyCareLink Patient Monitor 24950 |
| Version | 0 |
CVSS Information
| Base Score | 6.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
AI Analysis
| AI Description | Medtronic MyCareLink Patient Monitor has a vulnerability where a built-in user account has an empty password, allowing attackers with physical access to log in without credentials and modify system functionality. This affects models 24950 and 24952 before June 25, 2025. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Medtronic |
| AI Product | MyCareLink Patient Monitor |
| AI Version | 24950, 24952 |
Affected Products
- Medtronic MyCareLink Patient Monitor 24950 0
- Medtronic MyCareLink Patient Monitor 24952 0
Additional Information
| CWE List | CWE-258 |
|---|---|
| Source | Medtronic |
Description
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality.
This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025