Medtronic
First CVE: Aug 10, 2018Active for: 8 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
2.6
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Medtronic as a CNA, 61.5% affect products that Medtronic develops as a vendor.
61.5%
38.5%
Self-reported: 8Third-party: 5
Of all the CVEs published that affect products developed by Medtronic, 27.6% are self-published by Medtronic as a CNA.
27.6%
72.4%
Self-published: 8Published by other CNAs: 21
Trends Over Time
The number and severity of CVEs published by Medtronic over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 10, 2018
7 years ago
Most Recent CVE
May 7, 2026
81 days ago
Top CVEs
All CVEs published by Medtronic as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31222HIGH Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a | Jun 29, 2023 | 8.8 | 44 | NO | NO |
CVE-2025-12995CRITICAL Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certa | Dec 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4397MEDIUM Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data. | May 7, 2026 | 6.8 | 24 | NO | NO |
CVE-2025-4386MEDIUM Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal. | May 7, 2026 | 6.8 | 24 | NO | NO |
CVE-2018-10622HIGH Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication. | Aug 10, 2018 | 7.1 | 23 | NO | NO |
CVE-2025-4395MEDIUM Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify | Jul 24, 2025 | 6.8 | 21 | NO | NO |
CVE-2025-4394MEDIUM Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files.
This issue affect | Jul 24, 2025 | 6.8 | 21 | NO | NO |
CVE-2023-25931MEDIUM Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update | Mar 1, 2023 | 6.8 | 21 | NO | NO |
CVE-2025-12994MEDIUM Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user ac | Dec 4, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-4393MEDIUM Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to cras | Jul 24, 2025 | 6.5 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
69%
15%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (15.4%)
Network4 (30.8%)
Unknown0 (0.0%)
Physical6 (46.2%)
Adjacent Network1 (7.7%)
Attack Complexity
Low8 (61.5%)
High5 (38.5%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (30.8%)
High1 (7.7%)
None8 (61.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Medtronic as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Medtronic as a CNA — matched by CVE ID, not by organization name.