Back

MEDIUM

Medtronic MyCareLink Patient Monitor Use of Hard-coded Password

Published Jul 2, 2018

Description

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.

Affected products

Remediation

Vendor solution

Medtronic will release several rolling over-the-air product updates that will mitigate the vulnerabilities described within this advisory. These updates will be applied to devices automatically as part of standard, reoccurring update processes. In addition, Medtronic has increased security monitoring of affected devices and related infrastructure.

Medtronic has released additional patient focused information, at the following location:

https://www.medtronic.com/security

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jul 2, 2018
Updated May 22, 2025
Reserved Mar 20, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a