CVE-2025-4395
BaseFortify
Publication date: 2025-07-24
Last updated on: 2026-03-27
Assigner: Medtronic
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| medtronic | mycarelink_patient_monitor | 24950 |
| medtronic | mycarelink_patient_monitor | 24952 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-258 | Using an empty string as a password is insecure. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in Medtronic MyCareLink Patient Monitor involves a built-in user account that has an empty password. This allows an attacker with physical access to the device to log in without needing a password and gain the ability to access and modify system functionality.
How can this vulnerability impact me? :
This vulnerability can allow an attacker with physical access to the affected Medtronic MyCareLink Patient Monitor devices to gain unauthorized access and modify system functionality. This could lead to compromised device operation, potentially affecting patient monitoring and safety.