PT-2018-1432 · Medtronic · Medtronic Mycarelink Patient Monitor

Billy Rios

+2

·

Published

2018-08-07

·

Updated

2026-05-19

·

CVE-2018-10622

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medtronic MyCareLink Patient Monitor versions (affected versions not specified)
Description A vulnerability was discovered in Medtronic MyCareLink Patient Monitor, where per-product credentials are stored in a recoverable format. This allows an attacker to use these credentials for network authentication and encryption of local data at rest, potentially revealing protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00981
CVE-2018-10622

Affected Products

Medtronic Mycarelink Patient Monitor