CVE 2.2 LOW

CVE-2025-12997_CVE-2025-12997

2.2 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Description

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.

Basic Information

ID CVE-2025-12997
Source Medtronic
Published Dec 4, 2025 at 20:04

Affected Product

Vendor Medtronic
Product CareLink Network
Affected Versions Medtronic CareLink Network 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.