#VU113208 Empty Password in Configuration File in MyCareLink Patient Monitor model 24950 and MyCareLink Patient Monitor model 24952 - CVE-2025-4395

 

#VU113208 Empty Password in Configuration File in MyCareLink Patient Monitor model 24950 and MyCareLink Patient Monitor model 24952 - CVE-2025-4395

Published: July 25, 2025


Vulnerability identifier: #VU113208
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-4395
CWE-ID: CWE-258
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
MyCareLink Patient Monitor model 24950
MyCareLink Patient Monitor model 24952
Software vendor:
Medtronic

Description

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to the affected product has a built-in user account with an empty password. An attacker with physical access can log in with no password and access or modify system functionality.


Remediation

Install updates from vendor's website.

External links