QSearchQSearch

CVE-2018-10622

6.8 MEDIUM

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format

Published: 2018-08-10 · Last updated: 2026-05-19

Severity and scoring

CVSS
6.8 MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-313, CWE-522

Affected products

VendorProduct
medtronicmycarelink_24950_patient_monitor_firmware, mycarelink_24952_patient_monitor_firmware

Description

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2018-10626 Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded (4.4 MEDIUM)

Same CWE

  • CVE-2026-24349 A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All ver... (7.1 HIGH)
  • CVE-2026-41715 In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials (6.1 MEDIUM)
  • CVE-2026-39908 OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the N... (6.5 MEDIUM)
  • CVE-2026-46440 Flowise is a drag & drop user interface to build a customized large language model flow (9.1 CRITICAL)
  • CVE-2026-46511 HAX CMS helps manage microsite universe with PHP or NodeJs backends