Medtronic

First CVE: Aug 10, 2018Active for: 8 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
2.6
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Medtronic as a CNA, 61.5% affect products that Medtronic develops as a vendor.

61.5%
38.5%
Self-reported: 8Third-party: 5

Of all the CVEs published that affect products developed by Medtronic, 27.6% are self-published by Medtronic as a CNA.

27.6%
72.4%
Self-published: 8Published by other CNAs: 21

Trends Over Time

The number and severity of CVEs published by Medtronic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 10, 2018
7 years ago
Most Recent CVE
May 7, 2026
81 days ago

Top CVEs

All CVEs published by Medtronic as a CNA, regardless of affected vendor or product.

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a 
Jun 29, 20238.844NONO
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certa
Dec 4, 20259.830NONO
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
May 7, 20266.824NONO
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​
May 7, 20266.824NONO
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.
Aug 10, 20187.123NONO
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify
Jul 24, 20256.821NONO
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affect
Jul 24, 20256.821NONO
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update
Mar 1, 20236.821NONO
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user ac
Dec 4, 20255.319NONO
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to cras
Jul 24, 20256.519NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13 CVEs
Severity distribution among all CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local2 (15.4%)
Network4 (30.8%)
Unknown0 (0.0%)
Physical6 (46.2%)
Adjacent Network1 (7.7%)
Attack Complexity
Low8 (61.5%)
High5 (38.5%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (30.8%)
High1 (7.7%)
None8 (61.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Medtronic as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Medtronic as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs