User Account Vulnerability in Medtronic MyCareLink Patient Monitor Devices
CVE-2025-4395

6.8MEDIUM

What is CVE-2025-4395?

The Medtronic MyCareLink Patient Monitor contains a significant security issue where a built-in user account has an empty password. This flaw permits an attacker with physical access to the device to log in without any authentication, potentially enabling unauthorized modifications to system functionalities. This vulnerability affects specific models, including MyCareLink Patient Monitor 24950 and 24952, prior to the specified date in June 2025. Implementing secure password protocols is crucial to mitigate this risk and protect sensitive patient data.

Affected Version(s)

MyCareLink Patient Monitor 24950 0

MyCareLink Patient Monitor 24952 0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher
.
CVE-2025-4395 : User Account Vulnerability in Medtronic MyCareLink Patient Monitor Devices