Home
MEDIUM: 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before February 25, 2026
affected
Default status
unaffected
Any version before February 25, 2026
affected
Description
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.
Problem types
CWE-1263: Improper Physical Access Control
Product status
Any version before February 25, 2026
Any version before February 25, 2026
Credits
Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher
References
www.medtronic.com/...nk-patient-monitor-vulnerabilities.html
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-205-01