Internal Serial Interface Vulnerability in Medtronic MyCareLink Patient Monitor
CVE-2025-4386
6.8MEDIUM
Key Information:
- Vendor
Medtronic
- Vendor
- CVE Published:
- 7 May 2026
What is CVE-2025-4386?
The Medtronic MyCareLink Patient Monitor contains an internal serial interface that may be exploited by an attacker who has physical access to the device. This vulnerability allows unauthorized individuals to gain access to a login prompt through a UART terminal, posing significant security risks to patient data and device integrity.
Affected Version(s)
MyCareLink Patient Monitor 24950 0
MyCareLink Patient Monitor 24952 0
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher
