CVE 6.5 MEDIUM

Medtronic MyCareLink Patient Monitor Deserialization Vulnerability_CVE-2025-4393

6.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

Description

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

Basic Information

ID CVE-2025-4393
Source Medtronic
Published Jul 24, 2025 at 03:22
Modified Jul 24, 2025 at 14:33

Affected Product

Vendor Medtronic
Product MyCareLink Patient Monitor 24950
Affected Versions Medtronic MyCareLink Patient Monitor 24950 0
Medtronic MyCareLink Patient Monitor 24952 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.