Deserialization Vulnerability in Medtronic MyCareLink Patient Monitor
CVE-2025-4393
6.5MEDIUM
Key Information:
- Vendor
Medtronic
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-4393?
The Medtronic MyCareLink Patient Monitor is susceptible to a deserialization vulnerability due to its internal service that handles data deserialization. A local attacker may exploit this flaw by creating a specially crafted binary payload, allowing them to crash the service or potentially elevate their privileges. This vulnerability affects specific models 24950 and 24952, putting patient data and device functionality at risk. Remediation steps and further details are available on the Medtronic product security bulletin.
Affected Version(s)
MyCareLink Patient Monitor 24950 0
MyCareLink Patient Monitor 24952 0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ethan Morchy, with Somerset Recon
Carl Mann, independent researcher