Unencrypted Filesystem Vulnerability in Medtronic MyCareLink Patient Monitor
CVE-2025-4394
6.8MEDIUM
Key Information:
- Vendor
Medtronic
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-4394?
The Medtronic MyCareLink Patient Monitor suffers from a critical design flaw that utilizes an unencrypted filesystem for internal storage. This vulnerability exposes sensitive files to potential attackers with physical access, allowing them to read and modify critical data. The affected models, 24950 and 24952, are at risk if not addressed before the specified date of June 25, 2025. It is essential for users of these devices to remain vigilant to protect their personal health information.
Affected Version(s)
MyCareLink Patient Monitor 24950 0
MyCareLink Patient Monitor 24952 0
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher