Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Medtronic

166 known vulnerabilities

2
CRITICAL
7
HIGH
18
MEDIUM
1
LOW

Top Products

carelink network 4 valleylab ft10 energy platform firmware 4 valleylab ft10 energy platform 4 mycarelink smart model 25000 firmware 3 mycarelink smart model 25000 3 2090 carelink programmer firmware 3 2090 carelink programmer 3 valleylab exchange client 2 valleylab fx8 energy platform firmware 2 valleylab fx8 energy platform 2
28 CVEs
2.2
CVE-2025-12997

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with

4.1
CVE-2025-12996

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext

8.1
CVE-2025-12995

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint

5.3
CVE-2025-12994

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an

9.8
CVE-2023-31222

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and

6.4
CVE-2023-25931

Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, h

4.8
CVE-2022-32537

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai

8.8
CVE-2020-27252

Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys

8.8
CVE-2020-25187

Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent

8.0
CVE-2020-25183

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authentica

5.8
CVE-2019-13543

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4

7.0
CVE-2019-13539

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4

4.6
CVE-2019-13535

In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl

4.8
CVE-2019-13531

In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl

7.1
CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood gluc

6.5
CVE-2019-6540

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v

9.3
CVE-2019-6538

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v

4.6
CVE-2018-18984

Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa

4.8
CVE-2018-10634

Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently

4.4
CVE-2018-10626

Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded

5.2
CVE-2018-10622

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c

6.3
CVE-2018-10631

The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical

6.4
CVE-2018-8870

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An atta

6.2
CVE-2018-8868

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of t

7.1
CVE-2018-10596

Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not

4.6
CVE-2018-8849

Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card d

4.8
CVE-2018-5448

Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could

4.9
CVE-2018-5446

Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.

Frequently Asked Questions

How many CVEs affect Medtronic?

Medtronic has 166 CVE records in our database, including 21 critical and 34 high severity vulnerabilities.

What are the most severe Medtronic vulnerabilities?

Medtronic has 21 critical severity (CVSS 9.0+) and 34 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Medtronic vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Medtronic products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Medtronic Vulnerabilities

CyberStrike scans your infrastructure for Medtronic vulnerabilities and provides real-time remediation guidance.

Get Started