CVE-2025-4397: Medtronic Mycarelink Patient Monitor 24950

Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

Affected products

Published 2026-05-07. Last modified 2026-06-17.