Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.
References
| Link | Resource |
|---|---|
| https://www.medtronic.com/en-us/e/product-security/security-bulletins/carelink-network-vulnerabilities.html | Vendor Advisory |
Configurations
History
22 Dec 2025, 18:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:medtronic:carelink_network:*:*:*:*:*:*:*:* | |
| References | () https://www.medtronic.com/en-us/e/product-security/security-bulletins/carelink-network-vulnerabilities.html - Vendor Advisory | |
| First Time |
Medtronic
Medtronic carelink Network |
04 Dec 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-04 20:16
Updated : 2025-12-22 18:09
NVD link : CVE-2025-12997
Mitre link : CVE-2025-12997
CVE.ORG link : CVE-2025-12997
JSON object : View
Products Affected
medtronic
- carelink_network
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
