CVE-2025-4386
Unauthorized UART Access in Medtronic MyCareLink Patient Monitor
Publication date: 2026-05-07
Last updated on: 2026-05-07
Assigner: Medtronic
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| medtronic | mycarelink_patient_monitor | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1263 | The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Medtronic MyCareLink Patient Monitor has an internal serial interface that can be accessed via a UART terminal. An attacker with physical access to the device can use this interface to reach a login prompt, potentially bypassing normal security controls.
How can this vulnerability impact me? :
This vulnerability allows an attacker with physical access to the device to access a login prompt through the internal serial interface. This could lead to unauthorized access, potentially compromising the confidentiality, integrity, and availability of the device and the data it handles.