PT-2025-30628 · Medtronic · Mycarelink Patient Monitor 24950+1

Published

2025-07-24

·

Updated

2025-08-07

·

CVE-2025-4393

CVSS v3.1

6.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medtronic MyCareLink Patient Monitor models 24950 and 24952 before June 25, 2025
Description The Medtronic MyCareLink Patient Monitor contains an internal service that deserializes data. A local attacker can interact with this service by crafting a binary payload, potentially leading to a service crash or privilege escalation.
Recommendations Update Medtronic MyCareLink Patient Monitor model 24950 to a version released on or after June 25, 2025. Update Medtronic MyCareLink Patient Monitor model 24952 to a version released on or after June 25, 2025.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-4393

Affected Products

Mycarelink Patient Monitor 24950
Mycarelink Patient Monitor 24952