Security Advisory

CVE-2025-4393

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-24 03:22:20
Last updated 2026-03-27 19:38:42
Assigner Medtronic
State PUBLISHED

Description

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025