← Back to home
ICSMA-18-219-01  ·  Published 2026-05-07  ·  View on CISA ICS-CERT ↗

Medtronic MyCareLink 24950 Patient Monitor (Update A)

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities may allow an attacker with physical access to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Remediations

  • Medtronic has made server-side updates to address the insufficient verification vulnerability identified in this advisory. Medtronic is implementing additional server-side mitigations to enhance data integrity and authenticity.
  • Medtronic recommends users take additional defensive measures to minimize the risk of exploitation. Specifically, users should:
  • Maintain good physical control over the home monitor.
  • Only use home monitors obtained directly from their healthcare provider or a Medtronic representative to ensure integrity of the system.
  • Medtronic has released additional patient focused information, at the following location:
  • https://www.medtronic.com/security
  • Users should follow CISA's guidance in the following areas:
  • Securing the Internet of Things
  • Home Network Security

Affected Vendors

Medtronic

Affected Products (2)

Medtronic · 24950 MyCareLink Monitor vers:all/*
Medtronic · 24952 MyCareLink Monitor vers:all/*

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more