CVE-2025-4395 Details
Description
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
A vulnerability exists in the Medtronic MyCareLink Patient Monitor models 24950 and 24952, prior to June 25, 2025. The issue arises from a built-in user account that has an empty password, enabling an attacker with physical access to log in without a password and modify system functionality.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2025CISA-ADP
Assessed Jul 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-258 | Empty Password in Configuration File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Medtronic MyCareLink Patient Monitor | < June 25, 2025 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2026 | CVE Modified | [email protected] |
| Jul 24, 2025 | New CVE Received | [email protected] |
Volerion