Medtronic manufactures a broad range of implantable and wearable medical devices alongside networked programming and remote-monitoring platforms that connect directly to patient care workflows, creating a high-stakes attack surface where vulnerabilities can affect clinical safety and device integrity. The vendor's vulnerability portfolio, while modest in volume, concentrates in its CardiLink remote-management ecosystem and ValleyLab surgical energy platforms, with recurring weakness classes centered on authentication gaps, access-control deficiencies, and cleartext transmission of sensitive data—exposures particularly concerning in medical-device contexts where operational integrity and patient privacy are interdependent. A meaningful share of the vendor's disclosures reach serious severity, reflecting the control and data-access implications of networked medical infrastructure. Defenders should prioritize inventory and segmentation of Medtronic networked devices, coordinate updates through clinical engineering channels, and treat authentication and encryption gaps in these products as high-risk even when exploit activity is not the primary concern. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Medtronic over time
Of all the CVEs published by Medtronic as a CNA, 61.5% affect products that Medtronic develops as a vendor.
Of all the CVEs published that affect products developed by Medtronic, 27.6% are self-published by Medtronic as a CNA.
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31222HIGH Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a | Jun 29, 2023 | 8.8 | 44 | NO | NO |
CVE-2025-12995CRITICAL Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certa | Dec 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-25187CRITICAL Medtronic MyCareLink Smart 25000 is
vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event withi | Dec 14, 2020 | 9.8 | 28 | NO | NO |
CVE-2019-10964HIGH Medtronic MiniMed Insulin Pumps
are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB de | Jun 28, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-27252HIGH Medtronic MyCareLink Smart 25000 is
vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and execu | Dec 14, 2020 | 8.1 | 25 | NO | NO |
CVE-2020-25183HIGH Medtronic MyCareLink Smart 25000 contains
an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic My | Dec 14, 2020 | 8.8 | 25 | NO | NO |
CVE-2019-13539HIGH Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) | Nov 8, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-13543HIGH Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) | Nov 8, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-6538MEDIUM The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria | Mar 25, 2019 | 6.5 | 23 | NO | NO |
CVE-2018-10622HIGH Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication. | Aug 10, 2018 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Medtronic.
Media articles that mention a CVE ID that affects a product developed by Medtronic — matched by CVE ID, not by vendor name.