Medtronic MyCareLink Patient Monitor Empty Password Vulnerability

CVE Details

Basic Information

Title Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
Type cve
Published 2025-07-24T03:30:24.185Z
Modified 2025-07-24T03:30:24.185Z

Product Information

Vendor Medtronic
Product MyCareLink Patient Monitor 24950
Version 0

CVSS Information

Base Score 6.8 (MEDIUM)
Attack Vector CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Analysis

AI Description Medtronic MyCareLink Patient Monitor has a vulnerability where a built-in user account has an empty password, allowing attackers with physical access to log in without credentials and modify system functionality. This affects models 24950 and 24952 before June 25, 2025.
AI Severity Medium
AI Vendor Medtronic
AI Product MyCareLink Patient Monitor
AI Version 24950, 24952

Affected Products

  • Medtronic MyCareLink Patient Monitor 24950 0
  • Medtronic MyCareLink Patient Monitor 24952 0

Additional Information

CWE List CWE-258
Source Medtronic

Description

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.