VulnSea

carelink_network vulnerabilities

CVEs whose affected-version data names the carelink_network package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2025-12997Low· 2.2
9mo ago

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive…

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive…

▾ Sunlitmedtronic · carelink_networkEPSS 0.18%via NVD
CVE-2025-12996Medium· 4.1
9mo ago

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

▾ Sunlitmedtronic · carelink_networkEPSS 0.11%via NVD
CVE-2025-12995High· 8.1
9mo ago

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: be…

▾ Twilightmedtronic · carelink_networkEPSS 0.33%via NVD
CVE-2025-12994Medium· 5.3
9mo ago

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before Decemb…

▾ Sunlitmedtronic · carelink_networkEPSS 0.30%via NVD
carelink_network vulnerabilities (CVEs) · VulnSea