CVE-2025-4393 is a deserialization vulnerability (CWE-502) in Medtronic MyCareLink Patient Monitor models 24950 and 24952, affecting versions prior to June 25, 2025. A local attacker can exploit an internal service by crafting a binary payload, potentially leading to a service crash or privilege escalation. This vulnerability carries a CVSS score of 6.5 (MEDIUM), characterized by a local attack vector and high attack complexity, resulting in high impacts to integrity and availability, with low confidentiality. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Medtronic | MyCareLink Patient Monitor 24950 | >= 0, < June 25, 2025CNA affecteddefault unaffected | |
| Medtronic | MyCareLink Patient Monitor 24952 | >= 0, < June 25, 2025CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.