PT-2025-49127 · Medtronic · Medtronic Carelink Network

Ionut Cernica

·

Published

2025-12-04

·

Updated

2025-12-22

·

CVE-2025-12997

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Medtronic CareLink Network versions prior to December 4, 2025
Description An Insecure Direct Object Reference issue exists in Medtronic CareLink Network. An authenticated attacker, possessing access to specific device and user information, can submit web requests to an API endpoint and potentially expose sensitive user information. The vulnerable API endpoint is not specified. The vulnerable parameters or variables are not specified.
Recommendations Update Medtronic CareLink Network to a version released on or after December 4, 2025.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-12997

Affected Products

Medtronic Carelink Network