CVE-2025-12997
Estado: AnalizadaBaja (3.1)—
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-639
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-12997",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-12997",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-09T19:39:43.231608Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@medtronic.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.2,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 0.7
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security@medtronic.com",
"affectedData": [
{
"vendor": "Medtronic",
"product": "CareLink Network",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "December 4, 2025",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-12-04T20:16:17.480",
"references": [
{
"url": "https://www.medtronic.com/en-us/e/product-security/security-bulletins/carelink-network-vulnerabilities.html",
"tags": [
"Vendor Advisory"
],
"source": "security@medtronic.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@medtronic.com",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025."
},
{
"lang": "es",
"value": "Vulnerabilidad de Referencia Directa a Objeto Insegura en Medtronic CareLink Network que permite a un atacante autenticado con acceso a información específica de dispositivos y usuarios enviar solicitudes web a un endpoint de API que expondría información sensible del usuario. Este problema afecta a CareLink Network: antes del 4 de diciembre de 2025."
}
],
"lastModified": "2026-09-25T23:10:00.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:medtronic:carelink_network:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F732E0FA-C285-4923-873F-3080AC1032F8",
"versionEndExcluding": "2025-12-04"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@medtronic.com"
}