Medium severity4.6NVD Advisory· Published Dec 14, 2018· Updated Jun 17, 2026
CVE-2018-18984
CVE-2018-18984
Description
Medtronic CareLink and Encore Programmers
do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- cpe:2.3:o:medtronic:29901_encore_programmer_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:medtronic:carelink_2090_programmer_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:medtronic:carelink_9790_programmer_firmware:*:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: All versions
All versions+ 1 more
- (no CPE)range: All versions
- (no CPE)range: All versions
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/106215nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSMA-18-347-01nvdThird Party AdvisoryUS Government Resource
- global.medtronic.com/xg-en/product-security/security-bulletins/carelink-9790-2090-29901.htmlnvd
News mentions
0No linked articles in our index yet.