← Back

Medtronic

medtronic

29 CVEs • 200 products

Products (200)

Click to collapse
Toggle

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Medtronic
1Carelink Network
Dec 22, 2025
Dec 4, 2025
N/A· v4
3.1 LOW· v3
N/A· v2
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would...Show more
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.Show less
1Medtronic
1Carelink Network
Dec 22, 2025
Dec 4, 2025
N/A· v4
4.1 MEDIUM· v3
N/A· v2
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: befor...Show more
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.Show less
1Medtronic
1Carelink Network
Dec 22, 2025
Dec 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects Car...Show more
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.Show less
1Medtronic
1Carelink Network
Dec 22, 2025
Dec 4, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Netwo...Show more
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.Show less
1Medtronic
1Paceart Optima
Nov 21, 2024
Jun 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Pacea...Show more
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity.Show less
1Medtronic
2Interstim X Clinician
Micro Clinician
Nov 21, 2024
Mar 1, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially...Show more
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy application, which has greater control over therapy parameters than the patient app. Changes still cannot be made outside of the established therapy parameters of the programmer. For unauthorized access to occur, an individual would need physical access to the Smart Programmer. Show less
1Medtronic
28Guardian Link 2 Transmitter Mmt 7730 Firmware
Guardian Link 2 Transmitter Mmt 7731 FirmwareGuardian Link 2 Transmitter Mmt 7738 Firmware+25 more
May 7, 2026
Dec 12, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requir...Show more
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidanceShow less
1Medtronic
1Mycarelink Smart Model 25000 Firmware
May 22, 2025
Dec 14, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited,...Show more
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.Show less
1Medtronic
1Mycarelink Smart Model 25000 Firmware
May 22, 2025
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software...Show more
Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software stack. The heap overflow could allow an attacker to remotely execute code on the MCL Smart Patient Reader, potentially leading to control of the deviceShow less
1Medtronic
1Mycarelink Smart Model 25000 Firmware
May 22, 2025
Dec 14, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable...Show more
Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.Show less
1Medtronic
3Valleylab Exchange Client
Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform Firmware
May 22, 2025
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use mu...Show more
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.Show less
1Medtronic
3Valleylab Exchange Client
Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform Firmware
May 22, 2025
Nov 8, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use th...Show more
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.Show less
1Medtronic
2Valleylab Ft10 Energy Platform Firmware
Valleylab Ls10 Energy Platform Firmware
May 22, 2025
Nov 8, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the...Show more
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.Show less
1Medtronic
2Valleylab Ft10 Energy Platform Firmware
Valleylab Ls10 Energy Platform Firmware
May 22, 2025
Nov 8, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the...Show more
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism used for authentication between the FT10/LS10 Energy Platform and instruments can be bypassed, allowing for inauthentic instruments to connect to the generator.Show less
1Medtronic
19Minimed 508 Firmware
Minimed Paradigm 511 FirmwareMinimed Paradigm 512 Firmware+16 more
May 22, 2025
Jun 28, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication pr...Show more
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.Show less
1Medtronic
23Amplia Crt D Firmware
Carelink 2090 FirmwareCarelink Monitor 2490c Firmware+20 more
May 22, 2025
Mar 26, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Co...Show more
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.Show less
1Medtronic
20Amplia Crt D Firmware
Carelink 2090 FirmwareCarelink Monitor Firmware+17 more
May 22, 2025
Mar 25, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Co...Show more
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement authentication or authorization. An attacker with adjacent short-range access to an affected product, in situations where the product’s radio is turned on, can inject, replay, modify, and/or intercept data within the telemetry communication. This communication protocol provides the ability to read and write memory values to affected implanted cardiac devices; therefore, an attacker could exploit this communication protocol to change memory in the implanted cardiac device.Show less
1Medtronic
329901 Encore Programmer Firmware
Carelink 2090 Programmer FirmwareCarelink 9790 Programmer Firmware
May 22, 2025
Dec 14, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
1Medtronic
9Minimed 530g Mmt 551 Firmware
Minimed 530g Mmt 751 FirmwareMinimed Paradigm 508 Insulin Pump Firmware+6 more
May 22, 2025
Aug 13, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as devic...Show more
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.Show less
1Medtronic
2Mycarelink 24950 Patient Monitor Firmware
Mycarelink 24952 Patient Monitor Firmware
May 19, 2026
Aug 10, 2018
N/A· v4
4.4 MEDIUM· v3
3.8 LOW· v2
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac...Show more
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.Show less