- Description
- A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected products use per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 7.1
- Impact score
- 6
- Exploitability score
- 0.5
- Vector string
- CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 1.9
- Impact score
- 2.9
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:medtronic:mycarelink_24952_patient_monitor_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4008DB3-E151-41BA-A308-7BE733268845"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:medtronic:mycarelink_24952_patient_monitor:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "60267DCC-89D0-48E3-B6EB-9AD60DC1F16F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:medtronic:mycarelink_24950_patient_monitor_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8AACDB33-1EC3-44E1-8C1C-38C766E85F85"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:medtronic:mycarelink_24950_patient_monitor:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BCDA4070-6CDD-42CA-A4A8-DA6B0E98C64D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]