PT-2025-30629 · Medtronic · Mycarelink Patient Monitor

Published

2025-07-24

·

Updated

2025-08-25

·

CVE-2025-4394

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medtronic MyCareLink Patient Monitor versions 24950 and 24952 before June 25, 2025
Description The Medtronic MyCareLink Patient Monitor utilizes an unencrypted filesystem on its internal storage. This allows an attacker with physical access to read and modify files stored on the device.
Recommendations Ensure that physical access to the Medtronic MyCareLink Patient Monitor models 24950 and 24952 is restricted before June 25, 2025.

Fix

LPE

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-4394

Affected Products

Mycarelink Patient Monitor