CVE-2025-4395CWE-258

Medtronic MyCareLink Patient Monitor Empty Password Vulnerability

Medium · published July 24, 2025

CVSS v3.1
6.8
EPSS
0%
Percentile
18.9
In the wild
Unconfirmed
What it is

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00270 · 18.9th percentile
Weakness
CWE-258 · Empty Password in Configuration File
Published
2025-07-24T03:30Z
EPSS history
Timeline
  • 24 JUL 03:30Z
    Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
    cvelistv5