Medtronic
166 known vulnerabilities
Top Products
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, h
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys
Medtronic MyCareLink Smart 25000 is vulnerable when an authenticated attacker runs a debug command, which can be sent
Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authentica
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood gluc
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An atta
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of t
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not
Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card d
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
Frequently Asked Questions
How many CVEs affect Medtronic?
Medtronic has 166 CVE records in our database, including 21 critical and 34 high severity vulnerabilities.
What are the most severe Medtronic vulnerabilities?
Medtronic has 21 critical severity (CVSS 9.0+) and 34 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Medtronic vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Medtronic products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Medtronic Vulnerabilities
CyberStrike scans your infrastructure for Medtronic vulnerabilities and provides real-time remediation guidance.
Get Started