CVE Vulnerabilities

CVE-2025-4394

Cleartext Storage of Sensitive Information

Published: Jul 24, 2025 | Modified: Jul 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Potential Mitigations

References