Information Disclosure in Medtronic MyCareLink Patient Monitor
CVE-2018-8870
6.8MEDIUM
What is CVE-2018-8870?
The Medtronic MyCareLink Patient Monitor and its models 24950 and 24952 contain a critical security flaw due to hard-coded operating system passwords. This vulnerability allows an attacker with physical access to the device to exploit the debug port, thereby gaining unauthorized privileged access to the operating system. Such access could lead to potential manipulation or extraction of sensitive data, posing significant risks to patient privacy and device integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
24950 MyCareLink Monitor All versions
24952 MyCareLink Monitor All versions
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
