Description
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
Problem types
CWE-313 Cleartext storage in a file or on disk
Product status
Any version before February 25, 2026
Any version before February 25, 2026
Credits
Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher
Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC reported these vulnerabilities
References
www.medtronic.com/...nk-patient-monitor-vulnerabilities.html
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-205-01
www.medtronic.com/...curity-bulletins/mycarelink-8-7-18.html
www.cisa.gov/...vents/ics-medical-advisories/icsma-18-219-01