ZeroHour

CVE-2018-8870

CVSS 3.1
6.4 medium
EPSS
<1%p29
Published
()
Modified
Description

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.

Vendors
medtronic
Products
24950 mycarelink monitor firmware, 24952 mycarelink monitor firmware
Weakness
CWE-259, CWE-798
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.