CVE-2025-4397
Medtronic MyCareLink Patient Monitor Credential Exposure
Publication date: 2026-05-07
Last updated on: 2026-05-07
Assigner: Medtronic
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| medtronic | mycarelink_patient_monitor | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-313 | The product stores sensitive information in cleartext in a file, or on disk. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in Medtronic MyCareLink Patient Monitor involves the use of per-product credentials that are stored in a recoverable format. This means an attacker can potentially retrieve these credentials and use them to modify encrypted data on the device's drive.
How can this vulnerability impact me? :
This vulnerability can have a significant impact as an attacker who obtains the recoverable credentials can modify encrypted drive data. This could lead to unauthorized changes in the device's data, potentially compromising the integrity, confidentiality, and availability of patient information.