← Back

Medtronic

medtronic

29 CVEs • 200 products

Products (200)

Click to collapse
Toggle

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Medtronic
2Mycarelink 24950 Patient Monitor Firmware
Mycarelink 24952 Patient Monitor Firmware
Jun 22, 2026
Aug 10, 2018
N/A· v4
7.1 HIGH· v3
1.9 LOW· v2
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.
1Medtronic
2N'vision 8840 Firmware
N'vision 8870 Firmware
Aug 26, 2025
Jul 13, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of t...Show more
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.Show less
1Medtronic
224950 Mycarelink Monitor Firmware
24952 Mycarelink Monitor Firmware
Jun 17, 2026
Jul 3, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the...Show more
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.Show less
1Medtronic
224950 Mycarelink Monitor Firmware
24952 Mycarelink Monitor Firmware
Jun 17, 2026
Jul 3, 2018
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable c...Show more
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can exploit other vulnerabilities to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.Show less
1Medtronic
12090 Carelink Programmer Firmware
May 22, 2025
Jul 3, 2018
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affect...Show more
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initially establish an encapsulated IP-based VPN connection to a Medtronic-hosted update network. Once the VPN is established, it makes a request to a HTTP (non-TLS) server across the VPN for updates, which responds and provides any available updates. The programmer-side (client) service responsible for this HTTP request does not check to ensure it is still connected to the VPN before making the HTTP request. Thus, an attacker could cause the VPN connection to terminate (through various methods and attack points) and intercept the HTTP request, responding with malicious updates via a man-in-the-middle attack. The affected products do not verify the origin or integrity of these updates, as it insufficiently relied on the security of the VPN. An attacker with remote network access to the programmer could influence these communications.Show less
1Medtronic
2N'vision 8840 Firmware
N'vision 8870 Firmware
Jun 17, 2026
May 18, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.
1Medtronic
12090 Carelink Programmer Firmware
Jun 17, 2026
May 4, 2018
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.
1Medtronic
12090 Carelink Programmer Firmware
Jun 17, 2026
May 4, 2018
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
1Medtronic
1Paradigm Wireless Insulin Pump
Apr 29, 2026
Sep 2, 2011
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Medtronic Paradigm wireless insulin pump 512, 522, 712, and 722 allows remote attackers to modify the delivery of an insulin bolus dose and cause a denial of service (adverse human health eff...Show more
Unspecified vulnerability in Medtronic Paradigm wireless insulin pump 512, 522, 712, and 722 allows remote attackers to modify the delivery of an insulin bolus dose and cause a denial of service (adverse human health effects) via unspecified vectors involving wireless communications and knowledge of the device's serial number, as demonstrated by Jerome Radcliffe at the Black Hat USA conference in August 2011. NOTE: the vendor has disputed the severity of this issue, saying "we believe the risk of deliberate, malicious, or unauthorized manipulation of medical devices is extremely low... we strongly believe it would be extremely difficult for a third-party to wirelessly tamper with your insulin pump... you would be able to detect tones on the insulin pump that weren't intentionally programmed and could intervene accordingly."Show less