CVE-2018-10622

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:medtronic:mycarelink_24952_patient_monitor_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:mycarelink_24952_patient_monitor:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:medtronic:mycarelink_24950_patient_monitor_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:medtronic:mycarelink_24950_patient_monitor:-:*:*:*:*:*:*:*

History

22 May 2025, 16:15

Type Values Removed Values Added
References
  • () https://global.medtronic.com/xg-en/product-security/security-bulletins/mycarelink-8-7-18.html -
References (MISC) https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSMA-18-219-01 - Third Party Advisory, US Government Resource
References (BID) http://www.securityfocus.com/bid/105042 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105042 - Third Party Advisory, VDB Entry
Summary A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected products use per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest.

Information

Published : 2018-08-10 18:29

Updated : 2025-05-22 16:15


NVD link : CVE-2018-10622

Mitre link : CVE-2018-10622


JSON object : View

Products Affected

medtronic

  • mycarelink_24950_patient_monitor_firmware
  • mycarelink_24952_patient_monitor
  • mycarelink_24952_patient_monitor_firmware
  • mycarelink_24950_patient_monitor
CWE
CWE-522

Insufficiently Protected Credentials