Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Carelink Network CRITICAL 9.8
CVE-2025-12995

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determi…

Fix: 2025-12-04+
Fix from $2,300 2025-12-04
Carelink Network MEDIUM 5.3
CVE-2025-12994

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be us…

Fix: 2025-12-04+
Fix from $1,600 2025-12-04
Paceart Optima HIGH 8.8
CVE-2023-31222EPSS 28%

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an…

Fix: 1.12+
Fix from $1,950 2023-06-29
Interstim X Clinician MEDIUM 6.8
CVE-2023-25931

Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability …

Mitigation only
Fix from $1,600 2023-03-01
Mycarelink Smart Model 25000 Firmware CRITICAL 9.8
CVE-2020-25187

Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and ca…

Mitigation only
Fix from $2,300 2020-12-14
Mycarelink Smart Model 25000 Firmware HIGH 8.8
CVE-2020-25183

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Pati…

Mitigation only
Fix from $1,950 2020-12-14
Mycarelink Smart Model 25000 Firmware HIGH 8.1
CVE-2020-27252

Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned fi…

Mitigation only
Fix from $1,950 2020-12-14
Valleylab Exchange Client HIGH 7.8
CVE-2019-13539

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab…

Fix: after 4.0.0
Fix from $1,950 2019-11-08
Valleylab Exchange Client HIGH 7.5
CVE-2019-13543

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab…

Fix: after 4.0.0
Fix from $1,950 2019-11-08
Minimed 508 Firmware HIGH 7.1
CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr…

Mitigation only
Fix from $1,950 2019-06-28
Mycarelink Monitor 24950 Firmware MEDIUM 6.5
CVE-2019-6540

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…

Mitigation only
Fix from $1,600 2019-03-26
Mycarelink Monitor Firmware MEDIUM 6.5
CVE-2019-6538

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…

Mitigation only
Fix from $1,600 2019-03-25
Mycarelink 24952 Patient Monitor Firmware MEDIUM 5.2
CVE-2018-10622

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for …

Mitigation only
Fix from $1,600 2018-08-10
N\'vision 8840 Firmware MEDIUM 6.3
CVE-2018-10631

The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Applicatio…

Mitigation only
Fix from $1,600 2018-07-13
24950 Mycarelink Monitor Firmware MEDIUM 6.4
CVE-2018-8870

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can…

Mitigation only
Fix from $1,600 2018-07-03
24950 Mycarelink Monitor Firmware MEDIUM 6.2
CVE-2018-8868

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication in…

Mitigation only
Fix from $1,600 2018-07-03
2090 Carelink Programmer Firmware HIGH 7.1
CVE-2018-10596

Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected…

Mitigation only
Fix from $1,950 2018-07-03