PT-2025-49127 · Medtronic · Medtronic Carelink Network
Ionut Cernica
·
Published
2025-12-04
·
Updated
2025-12-22
·
CVE-2025-12997
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Medtronic CareLink Network versions prior to December 4, 2025
Description
An Insecure Direct Object Reference issue exists in Medtronic CareLink Network. An authenticated attacker, possessing access to specific device and user information, can submit web requests to an API endpoint and potentially expose sensitive user information. The vulnerable API endpoint is not specified. The vulnerable parameters or variables are not specified.
Recommendations
Update Medtronic CareLink Network to a version released on or after December 4, 2025.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Medtronic Carelink Network