CVE-2025-4386
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.16%
- CWE
- CWE-1263
- Published
- 2026-05-07
- Last modified
- 2026-05-07
Affected products
- Medtronic MyCareLink Patient Monitor 24950
- Medtronic MyCareLink Patient Monitor 24952
Weakness type
Related vulnerabilities
- CVE-2026-80253 — An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an...
- CVE-2025-6785 — Tesla Model 3 Physical CAN Bus Injection
- CVE-2025-8762 — INSTAR 2K+/4K UART improper physical access control
- CVE-2024-48973 — Debug port on Life2000 Ventilator serial interface is enabled by default
- CVE-2024-39512 — Junos OS Evolved: User is not logged out when the console cable is disconnected
- CVE-2022-48183
- CVE-2022-48182
- CVE-2022-3728