Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Medtronic

First CVE: Sep 2, 2011Active for: 15 yearsTotal CVEs: 29
14.6
VTI Score
Low

Medtronic manufactures a broad range of implantable and wearable medical devices alongside networked programming and remote-monitoring platforms that connect directly to patient care workflows, creating a high-stakes attack surface where vulnerabilities can affect clinical safety and device integrity. The vendor's vulnerability portfolio, while modest in volume, concentrates in its CardiLink remote-management ecosystem and ValleyLab surgical energy platforms, with recurring weakness classes centered on authentication gaps, access-control deficiencies, and cleartext transmission of sensitive data—exposures particularly concerning in medical-device contexts where operational integrity and patient privacy are interdependent. A meaningful share of the vendor's disclosures reach serious severity, reflecting the control and data-access implications of networked medical infrastructure. Defenders should prioritize inventory and segmentation of Medtronic networked devices, coordinate updates through clinical engineering channels, and treat authentication and encryption gaps in these products as high-risk even when exploit activity is not the primary concern. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Medtronic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2011
14 years ago
Most Recent CVE
Dec 4, 2025
234 days ago

Self-Reporting Analysis

Of all the CVEs published by Medtronic as a CNA, 61.5% affect products that Medtronic develops as a vendor.

61.5%
38.5%
Self-reported: 8 (61.5%)
Third-party: 5 (38.5%)

Of all the CVEs published that affect products developed by Medtronic, 27.6% are self-published by Medtronic as a CNA.

27.6%
72.4%
Self-published: 8 (27.6%)
Other CNAs: 21 (72.4%)

Products(200 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31222HIGH
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a 
Jun 29, 20238.844NONO
CVE-2025-12995CRITICAL
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certa
Dec 4, 20259.830NONO
CVE-2020-25187CRITICAL
Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event withi
Dec 14, 20209.828NONO
CVE-2019-10964HIGH
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB de
Jun 28, 20198.828NONO
CVE-2020-27252HIGH
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and execu
Dec 14, 20208.125NONO
CVE-2020-25183HIGH
Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic My
Dec 14, 20208.825NONO
CVE-2019-13539HIGH
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN)
Nov 8, 20197.824NONO
CVE-2019-13543HIGH
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN)
Nov 8, 20197.523NONO
CVE-2019-6538MEDIUM
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria
Mar 25, 20196.523NONO
CVE-2018-10622HIGH
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.
Aug 10, 20187.123NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
62%
28%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (6.9%)
Network7 (24.1%)
Unknown1 (3.4%)
Physical10 (34.5%)
Adjacent Network9 (31.0%)
Attack Complexity
Low20 (69.0%)
High8 (27.6%)
Unknown1 (3.4%)
User Interaction
None28 (96.6%)
Unknown1 (3.4%)
Required0 (0.0%)
Privileges Required
Low7 (24.1%)
High1 (3.4%)
None20 (69.0%)
Unknown1 (3.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Medtronic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Medtronic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Medtronic's Products

View all 3 CNAs →

Top CWEs