Information Disclosure in Medtronic MyCareLink Patient Monitor
CVE-2018-8870

6.8MEDIUM

Key Information:

Vendor

Medtronic

Vendor
CVE Published:
3 July 2018

What is CVE-2018-8870?

The Medtronic MyCareLink Patient Monitor and its models 24950 and 24952 contain a critical security flaw due to hard-coded operating system passwords. This vulnerability allows an attacker with physical access to the device to exploit the debug port, thereby gaining unauthorized privileged access to the operating system. Such access could lead to potential manipulation or extraction of sensitive data, posing significant risks to patient privacy and device integrity.

Affected Version(s)

24950 MyCareLink Monitor All versions

24952 MyCareLink Monitor All versions

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.