← Back to home
ICSMA-25-205-01  ·  Published 2026-05-07  ·  View on CISA ICS-CERT ↗

Medtronic MyCareLink Patient Monitor (Update A)

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could lead to system compromise, unauthorized access to sensitive data, and manipulation of the monitor's functionality.

Remediations

  • The identified vulnerabilities were reported as low-risk findings. An attacker would need to physically tamper with the monitor to exploit them. In response, starting in June 2025, Medtronic began deploying security updates to address these findings.
  • Medtronic recommends the following actions:
  • The security update process is performed automatically when the monitor is connected to the internet. Users should ensure that their remote monitor is plugged in to receive updates.
  • Physicians should continue to prescribe monitors as intended.
  • Users should maintain possession of their home monitor.
  • Users should only use home monitors provided directly from a healthcare provider or a Medtronic representative.
  • Users needing additional assistance should contact [email protected].
  • For more information regarding these vulnerabilities, refer to Medtronic's security bulletin.
  • Users should follow CISA's guidance in the following areas:
  • Securing the Internet of Things
  • Home Network Security

Affected Vendors

Medtronic

Affected Products (2)

Medtronic · MyCareLink Patient Monitor model 24950 vers:all/*
Medtronic · MyCareLink Patient Monitor model 24952 vers:all/*

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more