CVE-2020-25183 is an authentication bypass vulnerability affecting Medtronic MyCareLink Smart Model 25000 and its firmware. An attacker can exploit this flaw via Bluetooth to impersonate the legitimate mobile app, tricking the patient reader into communicating with an unauthorized device or application. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with an adjacent attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:medtronic:mycarelink_smart_model_25000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.