are stored in a recoverable format. An attacker can use these
credentials to modify encrypted drive data.
No analysis available yet.
Vendor Workaround
Medtronic recommends users take additional defensive measures to minimize the risk of exploitation. Specifically, users should: * Maintain good physical control over the home monitor. * Only use home monitors obtained directly from their healthcare provider or a Medtronic representative to ensure integrity of the system.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-2694 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. |
Tue, 19 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 19 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-257 |
Tue, 19 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data. |
| Title | Medtronic MyCareLink 24950 Patient Monitor Storing Passwords in a Recoverable Format | Medtronic MyCareLink 24950 Patient Monitor Cleartext Storage in a File or on Disk |
| Weaknesses | CWE-313 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 22 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected products use per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. |
| Title | Medtronic MyCareLink 24950 Patient Monitor Storing Passwords in a Recoverable Format | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-19T14:33:02.454Z
Reserved: 2018-05-01T00:00:00.000Z
Link: CVE-2018-10622
No data.
Status : Modified
Published: 2018-08-10T18:29:00.230
Modified: 2026-05-19T16:16:16.440
Link: CVE-2018-10622
No data.
OpenCVE Enrichment
No data.
EUVD