CVE-2025-4393 Information

Description

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25 2025

Reference

https://global.medtronic.com/xg-en/product-security/security-bulletins.html

Share on: