Statistics · Medical device cybersecurity

Medical Device Vulnerabilities: 536 CVEs, 12 on CISA's Exploited List

CISA's medical advisories directly name 536 distinct medical device vulnerabilities in 192 notices since 2016. Twelve (2.2%) are on CISA's exploited list, all Microsoft or Apache flaws, according to The PenTest Index's October 2026 analysis of CISA advisories. The often-quoted "6.2 per device" figure appears in a 2018 vendor blog post.

CISA is the U.S. cyber defense agency. A vulnerability is a security flaw. A CVE is a public ID for a disclosed flaw. Our exploited count means the flaw is on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Being off that list does not prove a flaw has never been used.

This page counts CVE IDs printed on CISA's advisory pages. One linked maker table adds 162 more IDs. It is not a safety rating for any device.

Key medical device vulnerability statistics

  • 536 vulnerabilities, 192 advisories. CISA published 192 medical device security advisories from March 29, 2016 to October 8, 2026. They directly name 536 different vulnerabilities (CVEs). (The PenTest Index analysis of CISA ICS medical advisories.)
  • 12 of 536 (2.2%) are on CISA's exploited list. Twelve are on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Eleven are Microsoft flaws and one is an Apache Tomcat flaw. None of these 12 catalog matches is a flaw in a device maker's own code. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • 0 of 77. No CISA medical advisory with a 2022 to 2026 number lists a CVE on CISA's exploited list as of October 8, 2026. The 12 sit in six advisories from 2017 to 2021. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • 49.4% are high or critical. Of the 512 vulnerabilities with a single CVSS v3 score, 253 are rated high or critical, and 93 (18.2%) are critical. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • 39.2% are access control flaws. 210 of the 536 fall in MITRE's access control group. 152 (28.4%) are authentication flaws: weak checks of a claimed identity. 42 (7.8%) are hard-coded or default passwords and keys. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • 76.8% need no prior privileges. 393 of the 512 scored vulnerabilities do not require the attacker to hold access rights before the attack. 257 (50.2%) can be reached over a network. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • Four makers, 45.8% of advisories. Philips (41), BD (23), Medtronic (15) and Baxter (9) are named in 88 of 192 advisories. In 2025 and 2026 they are named in 2 of 39. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
  • Imaging software: 10.0% to 48.4%. Imaging software was the subject of 13 of 130 advisories in 2016 to 2022 and 30 of 62 in 2023 to 2026. (The PenTest Index analysis of CISA medical advisories through October 8, 2026; device groups are our own sorting.)
  • Two older reports list 1,418 and 460 flaws. Two 2016 CISA advisories report these counts for outside software in two products without listing each CVE. Their sum is 1,878, but overlap is unknown, so it is not a count of 1,878 different flaws. (CISA advisories ICSMA-16-089-01 and ICSMA-16-196-01; sum by The PenTest Index.)
  • 11 of FDA's 18. Eleven of the 18 notices in the FDA's cybersecurity safety communications table (June 2013 to January 2025) match a CISA medical advisory in this dataset. (The PenTest Index matching, checked October 9, 2026 (UTC).)
  • 74.5% credit an outside or anonymous reporter. 143 of 192 advisories credit an outside or anonymous reporter with finding or reporting the flaw. 49 credit only the maker. (The PenTest Index reading of CISA medical advisories through October 8, 2026.)
  • The original "6.2 vulnerabilities per medical device" post gives no method. The earliest source we found is a February 7, 2018 Sensato blog post that gives no sample, dates or method. The FBI repeated the figure in 2022 and the GAO repeated the FBI in 2023.

Source for our counts: The PenTest Index analysis of CISA ICS medical advisories and the CISA Known Exploited Vulnerabilities catalog (version 2026.10.08). Data as of October 8, 2026.

The count at a glance

Key medical device vulnerability statistics
MeasureCountShare
CISA medical advisories, March 29, 2016 to October 8, 2026192
Different vulnerabilities (CVEs) named536100%
Rated high or critical (of 512 with a single score)25349.4%
On CISA's Known Exploited Vulnerabilities list122.2%
Device-maker-code flaws among the 12 catalog matches00% of the 12

Source: The PenTest Index analysis of CISA ICS medical advisories and the CISA Known Exploited Vulnerabilities catalog, October 8, 2026.

12 of 536 medical device vulnerabilities are on CISA's exploited listA grid of 536 squares. 12 are blue, for medical device vulnerabilities on CISA's Known Exploited Vulnerabilities list. 524 are grey.12 on CISA KEV524 not on the listSource: The PenTest Index analysis of CISA ICS medical advisories and CISA KEV catalog 2026.10.08. Data cutoffOctober 8, 2026; checked October 9, 2026 (UTC).
12 of 536 medical device vulnerabilities are on CISA's exploited listEach square is one CVE ID printed on a CISA medical advisory page, March 29, 2016 to October 8, 2026Download PNG

How many medical device vulnerabilities are there?

CISA's medical advisory pages directly name 536 medical device vulnerabilities in 192 advisories, from March 29, 2016 to October 8, 2026. That is about 18 advisories a year. The count covers flaws CISA has published, not every flaw that exists.

Think of an advisory as a security warning for software. One notice can cover one flaw or many. The biggest one here lists 35. Of the 188 notices that name CVEs, almost half (88) list just one.

How many advisories does CISA publish each year?

The busiest year was 2018, with 32 advisories. The quietest full year was 2023, with 10. In 2025 the count jumped back to 24, and 15 of those were about imaging software.

CISA medical advisories by year, 2016 to October 8, 2026

How many advisories does CISA publish each year?
YearAdvisoriesCVE listingsAbout imaging softwareNaming Philips, BD, Medtronic or Baxter
20164502
2017163326
201832123721
20192049114
20202488114
2021198818
20221526110
2023102635
2024132766
20252457152
2026 (to Oct 8)152960
Total1925514388

Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Year is the year in CISA's advisory number. Fifteen CVEs appear in two advisories, so the yearly listings add to 551, not 536. Device groups are our own sorting.

Imaging software went from a sliver to nearly half of advisoriesBars showing CISA medical advisories each year from 2016 to 2026. The imaging software part grows from 0 of 4 in 2016 to 15 of 24 in 2025.01020303542016162017322018202019242020192021152022102023132024242025152026 (to Oct 8)Imaging software (PACS and DICOM)Everything elseSource: The PenTest Index analysis of CISA ICS medical advisories. 2016 starts March 29; 2026 ends October 8.Checked October 9, 2026 (UTC).
Imaging software went from a sliver to nearly half of advisoriesCISA medical advisories per year. Imaging software: 13 of 130 in 2016–2022, 30 of 62 in 2023–2026Download PNG

What counts as one vulnerability?

One CVE counts as one vulnerability, no matter how many advisories repeat it. That is why the total is 536 and not 551.

  • Advisory: one notice from CISA. CISA calls these ICS medical advisories. Each has a number like ICSMA-25-030-01: the year, the day of the year, and a counter.
  • CVE: the public ID for one flaw.
  • Four advisories list no CVE numbers at all. They describe groups of flaws instead. They are counted in the 192.
  • The series starts in 2016. A few older medical notices carried a different kind of number and are not here.

How many medical device vulnerabilities are used in real attacks?

Twelve in this dataset are on CISA's exploited list. Of the 536 vulnerabilities, 12 (2.2%) are on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Eleven are Microsoft flaws and one is an Apache Tomcat flaw. None of these 12 catalog matches is a flaw in a device maker's own code.

CISA keeps a list of flaws that attackers have really used. A flaw gets on it only when three things are true: it has a CVE number, there is reliable evidence it has been actively exploited, and there is a clear action to address the flaw. CISA includes attempted as well as successful exploitation. Scanning, research and proof-of-concept code do not count.

Which 12 are known exploited?

All 12 are old flaws in common software: ten in Windows, one in Microsoft Office and one in Apache Tomcat. They show up in six advisories for imaging systems, a patient monitoring receiver and a drug-mixing system.

The 12 known exploited vulnerabilities named in CISA medical advisories

Which 12 are known exploited?
CVEName on CISA's listWhere it turns upAdvisoryAdded to the listRansomware use (per CISA)
CVE-2008-4250Microsoft Windows Buffer OverflowSiemens molecular imaging systems on Windows XPICSMA-17-215-01May 20, 2026Unknown
CVE-2015-1635Microsoft HTTP.sys Remote Code ExecutionSiemens molecular imaging systems on Windows 7ICSMA-17-215-02Feb 10, 2022Unknown
CVE-2017-0143Microsoft Windows Server Message Block (SMBv1) Remote Code ExecutionPhilips IntelliSpace Portal; Baxter ExactaMixICSMA-18-058-02; ICSMA-20-170-01Nov 3, 2021Known
CVE-2017-0144Microsoft SMBv1 Remote Code ExecutionPhilips IntelliSpace PortalICSMA-18-058-02Feb 10, 2022Known
CVE-2017-0145Microsoft SMBv1 Remote Code ExecutionPhilips IntelliSpace PortalICSMA-18-058-02Feb 10, 2022Known
CVE-2017-0146Microsoft Windows SMB Remote Code ExecutionPhilips IntelliSpace PortalICSMA-18-058-02Mar 25, 2022Known
CVE-2017-0147Microsoft Windows SMBv1 Information DisclosurePhilips IntelliSpace PortalICSMA-18-058-02May 24, 2022Known
CVE-2017-0148Microsoft SMBv1 Server Remote Code ExecutionPhilips IntelliSpace PortalICSMA-18-058-02Apr 6, 2022Known
CVE-2017-0199Microsoft Office and WordPad Remote Code ExecutionPhilips IntelliSpace PortalICSMA-18-058-02Nov 3, 2021Known
CVE-2017-7269Microsoft Windows Server Buffer OverflowSiemens molecular imaging systems on Windows XPICSMA-17-215-01Nov 3, 2021Unknown
CVE-2019-0708Microsoft Remote Desktop Services Remote Code ExecutionSpacelabs Xhibit Telemetry ReceiverICSMA-20-049-01Nov 3, 2021Known
CVE-2020-1938Apache Tomcat Improper Privilege ManagementPhilips Vue PACSICSMA-21-187-01Mar 3, 2022Unknown

Source: The PenTest Index match of CISA ICS medical advisories against the CISA Known Exploited Vulnerabilities catalog, version 2026.10.08 (1,739 entries), October 8, 2026.

Three things stand out.

  • The 12 sit in six advisories, all from 2017 to 2021.
  • No advisory numbered 2022 or later lists one (0 of 77).
  • The oldest carries a 2008 CVE number. CISA added it to its list on May 20, 2026.

One more flaw sits just outside this count. CVE-2023-43208, in NextGen Healthcare's Mirth Connect, has been on CISA's exploited list since May 20, 2024. No CISA medical advisory names it, so it is not one of the 536. CISA's September 2026 advisory for Mirth Connect (ICSMA-26-253-01) lists three other flaws.

Why are all 12 in borrowed software?

Many medical devices use common computer software. A device can inherit a flaw in the software it uses. All 12 catalog matches here are in that outside software.

  • CISA's Siemens advisory says the flaws are in imaging products "running on Windows XP".
  • CISA's Spacelabs advisory names the flaw BlueKeep and says an exploit "would be capable of rapidly spreading like the WannaCry malware attacks of 2017".
  • One 2016 advisory says a hospital supply cabinet (the CareFusion Pyxis SupplyStation) had 1,418 known flaws in 7 outside software packages. Another says a Philips system had 460: 272 in five software packages and 188 in Windows XP.
  • Add those reported counts: 1,418 + 460 = 1,878. The two lists may overlap with each other and with the 536 named CVEs, so we cannot call these 1,878 extra, different flaws. CISA's two pages put 715 and 360 at a score of 7.0 or higher: a reported sum of 1,075. These 2016 totals are kept apart from our CVSS v3 analysis.

Picture a house where the builder bought the front door lock from someone else. If that lock has a known trick, every house with that lock has the trick.

What does 12 of 536 not prove?

Twelve is the number of matches to CISA's catalog. It is not proof that the other 524 have never been used. CISA adds a flaw only with reliable evidence and a clear action to address it, so a quiet attack on one device may never make the list.

  • It does not mean devices are safe. Companies that scan hospital networks find known exploited flaws on real devices. Claroty reported in March 2025 that 9% of the connected medical devices it analyzed carried a known exploited flaw, across 99% of the 351 organizations in its sample.
  • Both numbers can be true. Ours counts flaws CISA named. Claroty's counts devices on hospital networks. In our data, the catalog matches are old Windows, Office and Tomcat flaws in device software.
  • One advisory hides a longer list. The Biosense Webster Carto 3 advisory (ICSMA-18-107-02) prints no CVE numbers. It points to a Johnson & Johnson table instead. We checked the original Johnson & Johnson PDF. It has 183 different CVE IDs, 21 already in our data and 162 more. Add those IDs and the set is 698, with 20 (2.9%) on CISA's exploited list: 19 Microsoft and one Apache. The pattern holds. The 183-row source file gives each PDF page and the match. Rows with only Microsoft bulletin or update numbers are not turned into extra CVEs.

Has a hacked medical device hurt a patient?

The FDA says it is not aware of one in the cases it lists. Its cybersecurity page lists 18 safety notices from June 2013 to January 2025 and says: "In each of the following cases, the FDA is not aware of any patient injuries or deaths associated with cybersecurity incidents."

That sentence covers those 18 cases. It is not a promise about every device.

  • The GAO, a federal watchdog, wrote in December 2023: "Although cyber incidents impacting medical devices have occurred, they are not common."
  • The FDA's 2026 guidance also warns: "Cyber incidents have rendered medical devices and hospital networks inoperable, disrupting the delivery of patient care."
  • The FDA's recall database lists 17 recall events that give "cybersecurity" in the reason, started between February 2019 and September 2026. This keyword search is not a full count of cybersecurity recalls or attacks. It returns 60 product records; we counted the 17 different recall event numbers.
  • Two other recall records name malware: a 2008 recall of an ultrasound imaging system warned of possible computer-worm infection; a 2021 recall of cloud-hosted cancer-care software gives its reason as "Malware attack".

How serious are medical device vulnerabilities?

About half are serious on paper. Of the 512 vulnerabilities with a single score, 253 (49.4%) are rated high or critical, and 93 (18.2%) are critical, the top band.

CVSS, the Common Vulnerability Scoring System, rates a flaw from 0 to 10. Not every flaw has a published score. Think of it like a storm rating. It tells you how strong the storm could be. It does not tell you whether it will hit your house.

Medical device vulnerabilities by severity (CVSS v3)

How serious are medical device vulnerabilities?
BandCVSS scoreVulnerabilitiesShare of 512
Critical9.0 to 10.09318.2%
High7.0 to 8.916031.3%
Medium4.0 to 6.923044.9%
Low0.1 to 3.9295.7%
High or critical7.0 to 10.025349.4%
All with a single score512100%

Source: The PenTest Index analysis of scores printed in CISA ICS medical advisories, October 8, 2026. Bands follow FIRST's CVSS v3.1 scale. Twenty-four vulnerabilities in one 2018 advisory have only a score range and are left out. Shares are rounded one at a time, so 18.2% and 31.3% look like 49.5%, but 253 of 512 is 49.4%.

Here is the odd part. Of the 93 critical flaws, 88 (94.6%) are not on the known exploited list. A scary score and a real attack are two different things.

How would an attacker reach a medical device?

Half have a network attack path. Of the 512 scored vulnerabilities, 257 (50.2%) can be reached over a network, and 393 (76.8%) need no prior privileges: access rights held before the attack.

Where the attacker has to be

How would an attacker reach a medical device?
Where the attacker has to beWhat it meansVulnerabilitiesShare of 512
NetworkAnywhere that can reach the device over a network. Like calling a phone number.25750.2%
AdjacentOn the same local or restricted network, or in radio range. Restricted-network access can be remote.11221.9%
LocalAlready on the device, or tricking a user into opening something.7815.2%
PhysicalHands on the device.6512.7%

Source: as stated in the linked source line or in each row.

What the attack requires

How would an attacker reach a medical device?
FactVulnerabilitiesShare of 512
No prior privileges needed39376.8%
No action by a user needed42783.4%
Rated low complexity (no special conditions beyond the attacker's control)39477.0%
All four at once: network, low complexity, no prior privileges, no user action14929.1%

Source: as stated in the linked source line or in each row.

Source for both tables: The PenTest Index analysis of CVSS v3 vectors printed in CISA ICS medical advisories, October 8, 2026. A vector records the conditions used to score a flaw. The FIRST definitions do not say every network-rated device is exposed to the public internet, or that a low-complexity attack is easy for anyone to carry out.

Half of scored medical device vulnerabilities can be reached over a networkA bar showing 50.2% of scored medical device vulnerabilities reachable over a network, 21.9% through an adjacent network or radio link, 15.2% on the device and 12.7% by touch.Where an attacker has to beNetwork50.2%Adjacent21.9%Local15.2%Physical12.7%76.8% need no prior privileges · 83.4% need no action by a user29.1% are network-reachable, low-complexity, need no prior privileges and no user actionSource: The PenTest Index analysis of CVSS v3 vectors in CISA ICS medical advisories; FIRST definitions. Datacutoff October 8, 2026; checked October 9, 2026 (UTC).
Half of scored medical device vulnerabilities can be reached over a networkWhere an attacker has to be, for the 512 vulnerabilities with a single CVSS v3 scoreDownload PNG

What do the scores leave out?

A score rates the software flaw. It does not rate what could happen to a patient. A flaw in a picture viewer and a flaw in an insulin pump can get the same number.

FIRST, the group that runs CVSS, says the base score measures severity, not risk.

What are the most common medical device vulnerabilities?

Access control flaws. Of the 536 vulnerabilities, 210 (39.2%) are access control flaws, which means the product does not check well enough who you are or what you are allowed to do. That is about 4.5 times the next kind.

The seven most common kinds of medical device vulnerability

What are the most common medical device vulnerabilities?
Kind (MITRE group)In plain wordsVulnerabilitiesShare of 536A real example
Access controlThe product does not check well enough who you are or what you may do.21039.2%GE medical imaging products that used default or hard-coded credentials (ICSMA-18-037-02)
EncryptionData is sent or stored without being scrambled, or the scrambling is weak.478.8%Medtronic heart-device radio link that sent data in the clear (ICSMA-19-080-01)
Memory safetyThe program reads or writes outside the memory it was given.478.8%Natus brain-wave (EEG) software, scored 10.0 (ICSMA-18-165-01)
InjectionThe product runs commands hidden in data someone sends it.356.5%Baxter Connex Health Portal, scored 10.0 (ICSMA-24-249-01)
Sensitive information exposureThe product shows private data to someone who should not see it.295.4%Dario Health blood glucose monitoring system (ICSMA-25-058-01)
Improper input validationThe product trusts what it is sent without checking it.285.2%Spacelabs telemetry receiver (ICSMA-20-049-01)
Resource lifecycle managementThe product mishandles files or resources. For example, it lets anyone upload any file.213.9%BD Alaris Gateway Workstation, scored 10.0 (ICSMA-19-164-01)

Source: The PenTest Index analysis. Weakness labels (CWEs) are the ones CISA printed. Groups are MITRE's CWE view 1400, not ours. Thirteen smaller groups hold 102 more vulnerabilities, and 17 use CWE category IDs that we keep ungrouped. Checked October 9, 2026 (UTC).

Access control flaws outnumber every other kindA bar chart. Access control has 210 medical device vulnerabilities, more than four times the next kinds, which have 47 each.050100150200250Access control210Encryption47Memory safety47Injection35Sensitive information exposure29Improper input validation28Resource lifecycle management21Other groups and unclassified119Vulnerabilities (of 536)Source: The PenTest Index analysis of CISA ICS medical advisories and MITRE CWE view 1400 (version 4.20). Datacutoff October 8, 2026; checked October 9, 2026 (UTC).
Access control flaws outnumber every other kind536 vulnerabilities in CISA medical advisories, grouped with MITRE's CWE view 1400Download PNG

How many are authentication and password flaws?

More than one in four. Of the 536 vulnerabilities, 152 (28.4%) are authentication flaws: the product does not check a claimed identity well enough. That includes logins, certificates and device identities. Forty-two (7.8%) are hard-coded or default passwords and keys.

The three sets nest like boxes: 210 access control flaws, 152 authentication flaws inside those, and 42 built-in passwords or keys inside those.

A built-in password is like a spare key that is the same for every house the builder ever made. Find it once and you can open them all.

  • The 42 sit in 37 advisories.
  • One GE advisory adds 23 more. CISA describes them as "default or hard-coded credentials" but files them under a broader label. With those it is 65 (12.1%).
  • Of the 93 critical flaws, 43 (46.2%) are authentication flaws.
  • The FDA's guidance asks makers to test for credentials that are "'hardcoded,' default, easily guessed, and easily compromised."

Which weakness labels does CISA use most?

Improper Authentication (CWE-287) is the most used single label, on 45 of the 536 vulnerabilities (8.4%). A CWE is a label for the kind of mistake behind a flaw.

Weakness labels on 10 or more vulnerabilities

Which weakness labels does CISA use most?
LabelOfficial nameVulnerabilitiesShare of 536
CWE-287Improper Authentication458.4%
CWE-20Improper Input Validation264.9%
CWE-798Use of Hard-coded Credentials234.3%
CWE-319Cleartext Transmission of Sensitive Information183.4%
CWE-284Improper Access Control183.4%
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')142.6%
CWE-259Use of Hard-coded Password132.4%
CWE-200Exposure of Sensitive Information to an Unauthorized Actor122.2%
CWE-306Missing Authentication for Critical Function122.2%
CWE-522Insufficiently Protected Credentials112.1%
CWE-787Out-of-bounds Write112.1%
CWE-311Missing Encryption of Sensitive Data101.9%
CWE-125Out-of-bounds Read101.9%

Source: The PenTest Index analysis of weakness labels printed in CISA ICS medical advisories; names from MITRE CWE. Checked October 9, 2026 (UTC).

A caution for anyone charting these. 167 of the 536 (31.2%) carry a label MITRE discourages or prohibits for mapping a specific flaw. Reasons include labels that are too broad, categories rather than weaknesses, and labels often confused with an attack's impact. That is why this page leads with groups.

Which medical devices and makers have the most vulnerabilities?

Imaging software has the most advisories: 43 of 192 (22.4%). Infusion pumps, medication and supply systems come next with 26, and patient monitors have 25. More advisories does not mean more danger.

A long list can mean more people are looking. It can also mean the maker reports its own flaws.

Which device types are named most?

Imaging machines have the highest share of high or critical flaws, at 76.6% (36 of 47). Heart devices (22.9%) and diabetes devices (19.4%) have the lowest.

CISA medical advisories and severity by device group

Which device types are named most?
Device groupAdvisoriesShare of 192Vulnerabilities with a scoreRated high or critical
Imaging software (PACS and DICOM)4322.4%9451 (54.3%)
Infusion pumps, medication and supply systems2613.5%9138 (41.8%)
Patient monitors, ECG and vital signs2513.0%6120 (32.8%)
Hospital software, apps and device connectivity2010.4%4833 (68.8%)
Surgery, therapy, shared parts and other189.4%6136 (59.0%)
Heart implants, programmers and home monitors147.3%358 (22.9%)
Lab and diagnostic instruments147.3%3517 (48.6%)
Imaging machines147.3%4736 (76.6%)
Diabetes devices and apps105.2%316 (19.4%)
Breathing, sleep and anesthesia84.2%199 (47.4%)

Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. The ten groups are our own sorting, and every row is in the data file so you can sort them your way. A vulnerability listed in two groups is counted in each. We use the same selected score for that CVE in both groups. For CVE-2017-0143, the imaging-software row uses the 8.1 score in Baxter's ICSMA-20-170-01; Philips' ICSMA-18-058-02 gives only a range. Using only scores printed in imaging advisories would give 50 high or critical flaws out of 93 scored (53.8%).

Two notes keep this table fair.

  • One GE advisory holds 23 of the 47 imaging machine flaws, all scored 9.8. Without it, imaging machines are 13 of 24 (54.2%).
  • Heart and diabetes devices have more limited attack paths in many of these scores. For 30 of the 35 heart-device flaws and 19 of the 31 diabetes-device flaws, the attacker needs adjacent-network or physical access. Attack path is one part of the score; this table does not prove why the groups differ.

Which makers are named most?

Four makers are named in almost half of all advisories. Philips, BD, Medtronic and Baxter account for 88 of 192 (45.8%). This is not a ranking of who is worst.

The eight makers named in the most CISA medical advisories

Which makers are named most?
MakerAdvisoriesShare of 192CVE listingsAdvisories crediting only the maker
Philips4121.4%12115
BD2312.0%4616
Medtronic157.8%335
Baxter94.7%347
Santesoft73.6%120
GE HealthCare63.1%360
B. Braun52.6%210
MicroDicom52.6%80

Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Each advisory is counted under one maker. Maker names are tidied by us.

  • There are 74 maker, vendor or software-project names in all, and 53 appear once. This includes software projects such as pydicom; it is not a count of 74 device manufacturers.
  • Hillrom is counted on its own (3 advisories). Baxter completed its purchase of Hillrom in December 2021.
  • BD is the only party credited in 16 of its 23 advisories. A maker that reports its own flaws will have a longer list.

Who finds or reports medical device vulnerabilities?

Mostly outside or anonymous reporters. Of the 192 advisories, 143 (74.5%) credit an outside or anonymous reporter, such as a security researcher or a hospital. The other 49 (25.5%) credit only the maker. An anonymous report does not tell us the reporter's affiliation.

In the versions we checked, 163 of 192 advisories (84.9%) used one of two narrower statements: no known public exploits, or no known public exploitation. Those statements do not mean the same thing.

Exploit wording on the advisory pages checked

Who finds or reports medical device vulnerabilities?
What the checked advisory saysAdvisoriesShare of 192
No known public exploits (older wording)10454.2%
No known public exploitation reported (newer wording)5930.7%
Public exploit code said to be available2110.9%
Nothing stated52.6%
Other wording31.6%

Source: The PenTest Index reading of the exploit statement in each CISA ICS medical advisory, checked October 9, 2026 (UTC). The analysis cutoff is October 8, 2026. "Public exploit code" means code that could be used in an attack was public. It does not mean the device was attacked.

How did the list change after 2023?

The list looks different now. In 2016 to 2022, the four big makers were named in 57.7% of advisories and imaging software was 10.0%. In 2023 to 2026, the four makers fell to 21.0% and imaging software rose to 48.4%.

Before and after 2023

How did the list change after 2023?
Measure2016 to 20222023 to 20262025 to 2026 only
Advisories1306239
About imaging software13 (10.0%)30 (48.4%)21 (53.8%)
Naming Philips, BD, Medtronic or Baxter75 (57.7%)13 (21.0%)2 (5.1%)
Crediting only the device maker40 (30.8%)9 (14.5%)0 (0.0%)

Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Device groups are our own sorting.

Of the 32 maker, vendor or project names in 2025 and 2026, 23 did not appear in the 2016–2024 medical-series advisories. The data shows the change. It does not explain it.

Which FDA cybersecurity alerts match a CISA advisory?

Eleven of the FDA's 18 cybersecurity safety notices match a CISA medical advisory in this dataset. Three more match a CISA advisory outside the medical series, three match broader CISA alerts, and one is general advice.

The FDA's table runs from June 13, 2013 to January 30, 2025. Nothing newer was in it when checked on October 9, 2026 (UTC).

FDA cybersecurity safety communications matched to CISA advisories

Which FDA cybersecurity alerts match a CISA advisory?
FDA dateFDA notice (short name)Matching CISA recordIn our 192?CVEs in the CISA record
Jan 30, 2025Contec and Epsimed patient monitorsICSMA-25-030-01Yes4
Sep 20, 2022Medtronic MiniMed 600 series insulin pumpsICSMA-22-263-01Yes1
Jun 2, 2022Illumina Local Run ManagerICSA-22-153-02No (not in the medical series)5
Mar 8, 2022PTC Axeda agent (shared software)ICSA-22-067-01No (not in the medical series)7
Dec 22, 2021Fresenius Kabi Agilia Connect infusion systemICSMA-21-355-01Yes13
Dec 17, 2021Apache Log4j (shared software)CISA alert, Dec 10, 2021No1
Aug 17, 2021BlackBerry QNX (shared software)AA21-229ANo1
Mar 3, 2020SweynTooth (shared Bluetooth software)ICS-ALERT-20-063-01No12
Jan 23, 2020GE Healthcare central stations and telemetry serversICSMA-20-023-01Yes6
Oct 1, 2019URGENT/11 (shared network software)ICSMA-19-274-01Yes11
Jun 27, 2019Medtronic MiniMed insulin pumpsICSMA-19-178-01Yes1
Mar 21, 2019Medtronic implantable heart devices, programmers and home monitorsICSMA-19-080-01Yes2
Oct 11, 2018Medtronic heart device programmersICSMA-18-058-01Yes3
Apr 17, 2018Abbott (formerly St. Jude Medical) implantable heart devicesICSMA-18-107-01Yes2
Aug 29, 2017Abbott (formerly St. Jude Medical) pacemakersICSMA-17-241-01Yes3
Jan 9, 2017St. Jude Medical heart devices and Merlin@home transmitterICSMA-17-009-01AYes1
May 13, 2015Hospira LifeCare PCA infusion pumpsICSA-15-125-01BNo (before the medical series)7
Jun 13, 2013Cybersecurity for medical devices and hospital networksNone (general advice)NoNot applicable

Source: FDA, Cybersecurity Safety Communications and Other Alerts, checked October 9, 2026 (UTC); matched by The PenTest Index to CISA advisories and CISA's published advisory files. "CVEs" counts ID numbers in the CISA record. It does not count attacks, patients or devices. The FDA's URGENT/11 press release links the medical advisory; the same flaws also appeared in ICSA-19-211-01. The Log4j and QNX counts cover the specific linked alerts, not every flaw in those software families.

Three things a writer should know before citing the FDA's table.

  • It is not a full history. The FDA sent a letter about Illumina's Universal Copy Service on April 27, 2023. That letter is not in the table. CISA's matching advisory, ICSMA-23-117-01, is in our dataset.
  • Advice changes after the first warning. The FDA updated its Contec notice on July 2, 2025 to say a patch exists. The FDA says the patch "fully removes networking functionality" and that patients and caregivers "should not install the software patch as the installation requires specialized expertise." Older text lower on the same page still says no patch is available.
  • Others have studied these 18. A March 2026 paper in Frontiers in Digital Health analyzed the same notices. Our part is the match to CISA's records.

How do I look up a medical device, maker or CVE?

Search the table below by maker, product or CVE number. It holds all 192 advisories, and each row links to CISA's own page. No match means this list has no record. It does not mean a product is safe.

Showing 192 of 192 advisories

All 192 CISA medical advisories in the dataset
Advisory IDProductMakerDevice groupCVE countTop CVSS v3Known exploited CVEsCreditedSource URLCheck date
ICSMA-26-253-02Orthanc DICOM Server
1 CVE listing
  • CVE-2026-87020 — Integer Overflow or Wraparound; CVSS v3 8.1; vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
OrthancImaging software (PACS and DICOM)18.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-253-01NextGen Healthcare Mirth Connect
3 CVE listings
  • CVE-2026-82583 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'); CVSS v3 8.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H; on CISA KEV: no
  • CVE-2026-78224 — Improper Restriction of XML External Entity Reference; CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L; on CISA KEV: no
  • CVE-2026-82578 — Improper Restriction of XML External Entity Reference; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
NextGen HealthcareHospital software, apps and device connectivity38.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-225-01Flow Neuroscience FL-100
1 CVE listing
  • CVE-2026-18164 — Use of Hard-coded Credentials; CVSS v3 8.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
Flow NeuroscienceSurgery, therapy, shared parts and other18.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-223-02Pulsetto Vagus Nerve Stimulator (Update A)
1 CVE listing
  • CVE-2026-18844 — Hidden Functionality; CVSS v3 8.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
PulsettoSurgery, therapy, shared parts and other18.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-223-01Mira Hormone Monitor, Mira Android App
8 CVE listings
  • CVE-2026-66875 — Missing Authentication for Critical Function; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2026-66098 — Missing Authentication for Critical Function; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2026-67558 — Authentication Bypass by Spoofing; CVSS v3 7.4; vector AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2026-67568 — Use of Hard-coded Credentials; CVSS v3 9.1; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2026-68067 — Weak Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2026-66340 — Improper Restriction of Excessive Authentication Attempts; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2026-64934 — Reliance on Untrusted Inputs in a Security Decision; CVSS v3 4.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2026-66832 — Use of HTTP Request With Sensitive Query String; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
Quanovate Tech (Mira)Lab and diagnostic instruments89.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-218-01Medixant RadiAnt DICOM
1 CVE listing
  • CVE-2026-17264 — Out-of-bounds Write; CVSS v3 4.3; vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L; on CISA KEV: no
MedixantImaging software (PACS and DICOM)14.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-216-01Thermo Fisher Applied Biosystems Genetic Analyzers
1 CVE listing
  • CVE-2026-17583 — Missing Support for Integrity Check; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
Thermo FisherLab and diagnostic instruments18.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-181-01OFFIS DCMTK Toolkit
5 CVE listings
  • CVE-2026-50003 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2026-50254 — Missing Release of Memory after Effective Lifetime; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2026-35505 — Missing Release of Memory after Effective Lifetime; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2026-52868 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2026-44628 — Access of Resource Using Incompatible Type ('Type Confusion'); CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
OFFISImaging software (PACS and DICOM)59.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-176-02OHIF Viewers DICOM
1 CVE listing
  • CVE-2026-12473 — Server-Side Request Forgery (SSRF); CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N; on CISA KEV: no
Open Health Imaging FoundationImaging software (PACS and DICOM)18.20Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-176-01pydicom pynetdicom Library
1 CVE listing
  • CVE-2026-56445 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 9.1; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
pydicomImaging software (PACS and DICOM)19.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-169-01Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
2 CVE listings
  • CVE-2026-50034 — Cleartext Transmission of Sensitive Information; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2026-52866 — Missing Authorization; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
Apollo PharmacyDiabetes devices and apps26.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-148-01Fourth Frontier Frontier X Mobile Application, Frontier X2
1 CVE listing
  • CVE-2026-5768 — Missing Authentication for Critical Function; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
Fourth FrontierPatient monitors, ECG and vital signs18.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-146-01Eppendorf BioFlo 320
1 CVE listing
  • CVE-2026-7251 — Use of Hard-coded Password; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
EppendorfLab and diagnostic instruments19.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-083-01Grassroots DICOM (GDCM)
1 CVE listing
  • CVE-2026-3650 — Missing Release of Memory after Effective Lifetime; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
Grassroots DICOMImaging software (PACS and DICOM)17.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-26-041-01ZOLL ePCR IOS Mobile Application
1 CVE listing
  • CVE-2025-12699 — Insertion of Sensitive Information into Externally-Accessible File or Directory; CVSS v3 5.5; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
ZOLLHospital software, apps and device connectivity15.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-364-01WHILL Model C2 Electric Wheelchairs and Model F Power Chairs (Update B)
1 CVE listing
  • CVE-2025-14346 — Missing Authentication for Critical Function; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
WHILLSurgery, therapy, shared parts and other19.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-345-02Varex Imaging Panoramic Dental Imaging Software
1 CVE listing
  • CVE-2024-22774 — Uncontrolled Search Path Element; CVSS v3 7.8; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
Varex ImagingImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-345-01Grassroots DICOM (GDCM)
1 CVE listing
  • CVE-2025-11266 — Out-of-bounds Write; CVSS v3 6.6; vector AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H; on CISA KEV: no
Grassroots DICOMImaging software (PACS and DICOM)16.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-336-01Mirion Medical EC2 Software NMIS BioDose
5 CVE listings
  • CVE-2025-64642 — Incorrect Permission Assignment for Critical Resource; CVSS v3 8.0; vector AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
  • CVE-2025-64298 — Incorrect Permission Assignment for Critical Resource; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-61940 — Use of Client-Side Authentication; CVSS v3 8.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2025-64778 — Use of Hard-coded Credentials; CVSS v3 7.3; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2025-62575 — Incorrect Permission Assignment for Critical Resource; CVSS v3 8.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
Mirion MedicalHospital software, apps and device connectivity58.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-301-01Vertikal Systems Hospital Manager Backend Services
2 CVE listings
  • CVE-2025-54459 — Exposure of Sensitive System Information to an Unauthorized Control Sphere; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2025-61959 — Generation of Error Message Containing Sensitive Information; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
Vertikal SystemsHospital software, apps and device connectivity27.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-296-01NIHON KOHDEN Central Monitor CNS-6201
1 CVE listing
  • CVE-2025-59668 — NULL Pointer Dereference; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
NIHON KOHDENPatient monitors, ECG and vital signs17.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-294-01Oxford Nanopore Technologies MinKNOW
3 CVE listings
  • CVE-2024-35585 — Missing Authentication for Critical Function; CVSS v3 8.6; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2025-54808 — Insufficiently Protected Credentials; CVSS v3 7.8; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-10937 — Improper Check for Unusual or Exceptional Conditions; CVSS v3 5.5; vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
Oxford Nanopore TechnologiesLab and diagnostic instruments38.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-233-01FUJIFILM Healthcare Americas Synapse Mobility
1 CVE listing
  • CVE-2025-54551 — External Control of Assumed-Immutable Web Parameter; CVSS v3 4.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
FujifilmImaging software (PACS and DICOM)14.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-224-01Santesoft Sante PACS Server
5 CVE listings
  • CVE-2025-0572 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 4.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
  • CVE-2025-53948 — Double Free; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2025-54156 — Cleartext Transmission of Sensitive Information; CVSS v3 7.4; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2025-54862 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 5.4; vector AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2025-54759 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 6.1; vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)57.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-205-01Medtronic MyCareLink Patient Monitor (Update A)
6 CVE listings
  • CVE-2025-4394 — Cleartext Storage of Sensitive Information; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-4395 — Empty Password in Configuration File; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-4393 — Deserialization of Untrusted Data; CVSS v3 6.5; vector AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
  • CVE-2018-10622 — Cleartext Storage in a File or on Disk; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-4386 — Improper Physical Access Control; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-4397 — Cleartext Storage in a File or on Disk; CVSS v3 6.5; vector AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors66.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-198-01Panoramic Corporation Digital Imaging Software
1 CVE listing
  • CVE-2024-22774 — Uncontrolled Search Path Element; CVSS v3 7.8; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PanoramicImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-160-01MicroDicom DICOM Viewer
1 CVE listing
  • CVE-2025-5943 — Out-of-bounds Write; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MicroDicomImaging software (PACS and DICOM)18.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-148-01Santesoft Sante DICOM Viewer Pro
1 CVE listing
  • CVE-2025-5307 — Out-of-bounds Read; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-128-01Pixmeo OsiriX MD
3 CVE listings
  • CVE-2025-27578 — Use After Free; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2025-31946 — Use After Free; CVSS v3 6.2; vector AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2025-27720 — Cleartext Transmission of Sensitive Information; CVSS v3 7.4; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
PixmeoImaging software (PACS and DICOM)37.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-121-01MicroDicom DICOM Viewer
2 CVE listings
  • CVE-2025-35975 — Out-of-bounds Write; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-36521 — Out-of-bounds Read; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MicroDicomImaging software (PACS and DICOM)28.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-100-01INFINITT Healthcare INFINITT PACS
3 CVE listings
  • CVE-2025-27714 — Unrestricted Upload of File with Dangerous Type; CVSS v3 6.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2025-24489 — Unrestricted Upload of File with Dangerous Type; CVSS v3 6.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2025-27721 — Exposure of Sensitive System Information to an Unauthorized Control Sphere; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
INFINITT HealthcareImaging software (PACS and DICOM)37.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-079-01Santesoft Sante DICOM Viewer Pro
1 CVE listing
  • CVE-2025-2480 — Out-of-bounds Write; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-072-01Philips Intellispace Cardiovascular (ISCV)
2 CVE listings
  • CVE-2025-2230 — Improper Authentication; CVSS v3 7.7; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2025-2229 — Use of Weak Credentials; CVSS v3 7.7; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)27.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-058-01Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application
7 CVE listings
  • CVE-2025-20060 — Exposure of Private Personal Information to an Unauthorized Actor; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2025-23405 — Improper Output Neutralization for Logs; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
  • CVE-2025-24843 — Storage of Sensitive Data in a Mechanism without Access Control; CVSS v3 5.1; vector AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
  • CVE-2025-24849 — Cleartext Transmission of Sensitive Information; CVSS v3 7.1; vector AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-20049 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 5.8; vector AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2025-24318 — Sensitive Cookie Without 'HttpOnly' Flag; CVSS v3 6.8; vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2025-24316 — Exposure of Sensitive Information Due to Incompatible Policies; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
Dario HealthDiabetes devices and apps77.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-051-01Medixant RadiAnt DICOM Viewer
1 CVE listing
  • CVE-2025-1001 — Improper Certificate Validation; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N; on CISA KEV: no
MedixantImaging software (PACS and DICOM)15.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-044-01Qardio Heart Health IOS and Android Application and QardioARM A100
3 CVE listings
  • CVE-2025-20615 — Exposure of Private Personal Information to an Unauthorized Actor; CVSS v3 6.2; vector AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2025-24836 — Uncaught Exception; CVSS v3 7.1; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
  • CVE-2025-23421 — Files or Directories Accessible to External Parties; CVSS v3 6.4; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
QardioPatient monitors, ECG and vital signs37.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-037-02Orthanc Server
1 CVE listing
  • CVE-2025-0896 — Missing Authentication for Critical Function; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
OrthancImaging software (PACS and DICOM)19.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-037-01MicroDicom DICOM Viewer
1 CVE listing
  • CVE-2025-1002 — Improper Certificate Validation; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N; on CISA KEV: no
MicroDicomImaging software (PACS and DICOM)15.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-25-030-01Contec Health CMS8000 Patient Monitor (Update A)
4 CVE listings
  • CVE-2024-12248 — Out-of-bounds Write; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-0626 — Hidden Functionality; CVSS v3 7.5; vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2025-0683 — Exposure of Private Personal Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2025-1204 — Hidden Functionality; CVSS v3 7.5; vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
Contec HealthPatient monitors, ECG and vital signs49.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-354-01Ossur Mobile Logic Application
3 CVE listings
  • CVE-2024-53683 — Exposure of Sensitive System Information to an Unauthorized Control Sphere; CVSS v3 4.4; vector AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
  • CVE-2024-54681 — Improper Neutralization of Special Elements used in a Command ('Command Injection'); CVSS v3 3.5; vector AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L; on CISA KEV: no
  • CVE-2024-45832 — Use of Hard-coded Credentials; CVSS v3 4.3; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
OssurSurgery, therapy, shared parts and other34.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-352-01BD Diagnostic Solutions Products (Update A)
1 CVE listing
  • CVE-2024-10476 — Use of Default Credentials; CVSS v3 8.0; vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDLab and diagnostic instruments18.00Device maker onlyCISA advisory2026-10-09
ICSMA-24-319-01Baxter Life2000 Ventilation System
9 CVE listings
  • CVE-2024-9834 — Cleartext Transmission of Sensitive Information; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-9832 — Improper Restriction of Excessive Authentication Attempts; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-48971 — Use of Hard-coded Credentials; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-48973 — Improper Physical Access Control; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-48974 — Download of Code Without Integrity Check; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-48970 — On-Chip Debug and Test Interface With Improper Access Control; CVSS v3 9.3; vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-8004 — Missing Support for Security Features in On-chip Fabrics or Buses; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2024-48966 — Missing Authentication for Critical Function; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-48967 — Insufficient Logging; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
BaxterBreathing, sleep and anesthesia910.00Device maker onlyCISA advisory2026-10-09
ICSMA-24-254-01BPL Medical Technologies PWS-01-BT and BPL Be Well Android Application
1 CVE listing
  • CVE-2024-34463 — Cleartext Transmission of Sensitive Information; CVSS v3 4.6; vector AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
BPL Medical TechnologiesPatient monitors, ECG and vital signs14.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-249-01Baxter Connex Health Portal
2 CVE listings
  • CVE-2024-6795 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'); CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-6796 — Improper Access Control; CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N; on CISA KEV: no
BaxterHospital software, apps and device connectivity210.00Device maker onlyCISA advisory2026-10-09
ICSMA-24-200-01Philips Vue PACS (Update A)
2 CVE listings
  • CVE-2021-28165 — Allocation of Resources Without Limits or Throttling; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2023-40704 — Use of Default Credentials; CVSS v3 6.8; vector AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)26.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-163-01MicroDicom DICOM Viewer
2 CVE listings
  • CVE-2024-33606 — Improper Authorization in Handler for Custom URL Scheme; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-28877 — Stack-based Buffer Overflow; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MicroDicomImaging software (PACS and DICOM)28.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-151-02Baxter Welch Allyn Connex Spot Monitor
1 CVE listing
  • CVE-2024-1275 — Use of Default Cryptographic Key; CVSS v3 7.4; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
BaxterPatient monitors, ECG and vital signs17.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-151-01Baxter Welch Allyn Configuration Tool
1 CVE listing
  • CVE-2024-5176 — Insufficiently Protected Credentials; CVSS v3 9.6; vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L; on CISA KEV: no
BaxterHospital software, apps and device connectivity19.60Device maker onlyCISA advisory2026-10-09
ICSMA-24-065-01Santesoft Sante FFT Imaging
1 CVE listing
  • CVE-2024-1696 — Out-of-bounds Write; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-060-01MicroDicom DICOM Viewer
2 CVE listings
  • CVE-2024-22100 — Heap-based Buffer Overflow; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-25578 — Out-of-bounds Write; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MicroDicomImaging software (PACS and DICOM)27.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-058-01Santesoft Sante DICOM Viewer Pro
1 CVE listing
  • CVE-2024-1453 — Out-of-bounds Read; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-24-023-01Orthanc Osimis DICOM Web Viewer
1 CVE listing
  • CVE-2023-7238 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 7.1; vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L; on CISA KEV: no
OrthancImaging software (PACS and DICOM)17.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-331-01BD FACSChorus
7 CVE listings
  • CVE-2023-29060 — Missing Protection Mechanism for Alternate Hardware Interface; CVSS v3 5.4; vector AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H; on CISA KEV: no
  • CVE-2023-29061 — Missing Authentication for Critical Function; CVSS v3 5.2; vector AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H; on CISA KEV: no
  • CVE-2023-29062 — Improper Authentication; CVSS v3 3.8; vector AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2023-29063 — Missing Protection Mechanism for Alternate Hardware Interface; CVSS v3 2.4; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2023-29064 — Use of Hard-coded Credentials; CVSS v3 4.1; vector AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2023-29065 — Insecure Inherited Permissions; CVSS v3 4.1; vector AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2023-29066 — Incorrect Privilege Assignment; CVSS v3 3.2; vector AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
BDLab and diagnostic instruments75.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-285-02Santesoft Sante FFT Imaging
1 CVE listing
  • CVE-2023-5059 — Out-of-bounds Read; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-285-01Santesoft Sante DICOM Viewer Pro
2 CVE listings
  • CVE-2023-39431 — Out-of-bounds Write; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2023-35986 — Stack-based Buffer Overflow; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
SantesoftImaging software (PACS and DICOM)27.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-248-01Softneta MedDream PACS
2 CVE listings
  • CVE-2023-40150 — Exposed Dangerous Method or Function; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2023-39227 — Plaintext Storage of a Password; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
SoftnetaImaging software (PACS and DICOM)29.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-194-01BD Alaris System with Guardrails Suite MX (Update A)
8 CVE listings
  • CVE-2023-30559 — Improper Input Validation; CVSS v3 5.2; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H; on CISA KEV: no
  • CVE-2023-30560 — Improper Authentication; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2023-30561 — Missing Encryption of Sensitive Data; CVSS v3 6.1; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H; on CISA KEV: no
  • CVE-2023-30562 — Insufficient Verification of Data Authenticity; CVSS v3 6.7; vector AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2023-30563 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2023-30564 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 6.9; vector AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2023-30565 — Cleartext Transmission of Sensitive Information; CVSS v3 3.5; vector AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2018-1285 — Improper Restriction of XML External Entity Reference; CVSS v3 3.0; vector AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
BDInfusion pumps, medication and supply systems88.20Device maker onlyCISA advisory2026-10-09
ICSMA-23-180-01Medtronic Paceart Optima System
1 CVE listing
  • CVE-2023-31222 — Deserialization of Untrusted Data; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors19.80Device maker onlyCISA advisory2026-10-09
ICSMA-23-117-01Illumina Universal Copy Service
2 CVE listings
  • CVE-2023-1968 — Binding to an Unrestricted IP Address; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2023-1966 — Execution with Unnecessary Privileges; CVSS v3 7.4; vector AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
IlluminaLab and diagnostic instruments210.00Device maker onlyCISA advisory2026-10-09
ICSMA-23-103-01B. Braun Battery Pack SP with Wi-Fi
1 CVE listing
  • CVE-2023-0888 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'); CVSS v3 5.5; vector AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L; on CISA KEV: no
B. BraunInfusion pumps, medication and supply systems15.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-23-061-01Medtronic Micro Clinician and InterStim Apps
1 CVE listing
  • CVE-2023-25931 — Unverified Password Change; CVSS v3 6.4; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
MedtronicSurgery, therapy, shared parts and other16.40Device maker onlyCISA advisory2026-10-09
ICSMA-23-047-01BD Alaris Infusion Central (Update A)
1 CVE listing
  • CVE-2022-47376 — Storing Passwords in a Recoverable Format; CVSS v3 7.3; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
BDInfusion pumps, medication and supply systems17.30Device maker onlyCISA advisory2026-10-09
ICSMA-22-335-01BD BodyGuard Pumps
1 CVE listing
  • CVE-2022-43557 — Missing Protection Mechanism for Alternate Hardware Interface; CVSS v3 5.3; vector AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems15.30Device maker onlyCISA advisory2026-10-09
ICSMA-22-298-01AliveCor KardiaMobile
2 CVE listings
  • CVE-2022-40703 — Authentication Bypass by Assumed-Immutable Data; CVSS v3 5.2; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N; on CISA KEV: no
  • CVE-2022-41627 — Missing Encryption of Sensitive Data; CVSS v3 4.8; vector AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H; on CISA KEV: no
AliveCorPatient monitors, ECG and vital signs25.20Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-277-01BD Totalys MultiProcessor
1 CVE listing
  • CVE-2022-40263 — Use of Hard-coded Credentials; CVSS v3 6.6; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L; on CISA KEV: no
BDLab and diagnostic instruments16.60Device maker onlyCISA advisory2026-10-09
ICSMA-22-263-01Medtronic NGP 600 Series Insulin Pumps
1 CVE listing
  • CVE-2022-32537 — Protection Mechanism Failure; CVSS v3 4.8; vector AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
MedtronicDiabetes devices and apps14.80Device maker onlyCISA advisory2026-10-09
ICSMA-22-251-01Baxter Sigma Spectrum Infusion Pump (Update A)
4 CVE listings
  • CVE-2022-26390 — Missing Encryption of Sensitive Data; CVSS v3 4.2; vector AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2022-26392 — Use of Externally-Controlled Format String; CVSS v3 3.1; vector AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2022-26393 — Use of Externally-Controlled Format String; CVSS v3 5.0; vector AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2022-26394 — Missing Authentication for Critical Function; CVSS v3 7.5; vector AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L; on CISA KEV: no
BaxterInfusion pumps, medication and supply systems47.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-244-01Contec Health CMS8000 Patient Monitor (Update A)
5 CVE listings
  • CVE-2022-36385 — Improper Physical Access Control; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2022-38100 — Allocation of Resources Without Limits or Throttling; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2022-38069 — Use of Hard-coded Credentials; CVSS v3 4.3; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2022-38453 — Active Debug Code; CVSS v3 3.0; vector AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2022-3027 — Unprotected Primary Channel; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H; on CISA KEV: no
Contec HealthPatient monitors, ECG and vital signs57.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-174-01OFFIS DCMTK
3 CVE listings
  • CVE-2022-2119 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 7.5; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2022-2120 — Relative Path Traversal; CVSS v3 7.5; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2022-2121 — NULL Pointer Dereference; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
OFFISImaging software (PACS and DICOM)37.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-167-01Hillrom Medical Device Management
2 CVE listings
  • CVE-2022-26388 — Use of Hard-coded Password; CVSS v3 6.4; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2022-26389 — Improper Access Control; CVSS v3 7.7; vector AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H; on CISA KEV: no
HillromPatient monitors, ECG and vital signs27.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-151-02BD Synapsys
1 CVE listing
  • CVE-2022-30277 — Insufficient Session Expiration; CVSS v3 5.7; vector AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N; on CISA KEV: no
BDLab and diagnostic instruments15.70Device maker onlyCISA advisory2026-10-09
ICSMA-22-151-01BD Pyxis
1 CVE listing
  • CVE-2022-22767 — Not Using Password Aging; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems18.80Device maker onlyCISA advisory2026-10-09
ICSMA-22-095-01LifePoint Informatics Patient Portal
1 CVE listing
  • CVE-2022-1067 — Authentication Bypass Using an Alternate Path or Channel; CVSS v3 6.5; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
LifePoint InformaticsHospital software, apps and device connectivity16.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-088-01Philips e-Alert
1 CVE listing
  • CVE-2022-0922 — Missing Authentication for Critical Function; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
PhilipsImaging machines16.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-22-062-02BD Viper LT
1 CVE listing
  • CVE-2022-22765 — Use of Hard-coded Credentials; CVSS v3 8.0; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
BDLab and diagnostic instruments18.00Device maker onlyCISA advisory2026-10-09
ICSMA-22-062-01BD Pyxis
1 CVE listing
  • CVE-2022-22766 — Use of Hard-coded Credentials; CVSS v3 7.0; vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems17.00Device maker onlyCISA advisory2026-10-09
ICSMA-22-006-01Philips Engage Software
1 CVE listing
  • CVE-2021-23173 — Improper Access Control; CVSS v3 2.6; vector AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsHospital software, apps and device connectivity12.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-355-01Fresenius Kabi Agilia Connect Infusion System (Update A)
13 CVE listings
  • CVE-2021-23236 — Uncontrolled Resource Consumption; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2021-31562 — Use of a Broken or Risky Cryptographic Algorithm; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2021-41835 — Use of a Broken or Risky Cryptographic Algorithm; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2021-23196 — Insufficiently Protected Credentials; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2021-23233 — Improper Access Control; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2021-23207 — Plaintext Storage of a Password; CVSS v3 6.5; vector AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2021-33843 — Files or Directories Accessible to External Parties; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
  • CVE-2021-23195 — Exposure of Information Through Directory Listing; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2021-33848 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2021-44464 — Use of Hard-coded Credentials; CVSS v3 6.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2021-33846 — Use of a Broken or Risky Cryptographic Algorithm; CVSS v3 5.9; vector AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2021-43355 — Use of Client-Side Authentication; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-35340 — Use of Unmaintained Third Party Components; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
Fresenius KabiInfusion pumps, medication and supply systems137.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-343-01Hillrom Welch Allyn Cardio Products
1 CVE listing
  • CVE-2021-43935 — Authentication Bypass Using an Alternate Path or Channel; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
HillromPatient monitors, ECG and vital signs18.10Device maker onlyCISA advisory2026-10-09
ICSMA-21-322-02Philips Patient Information Center iX (PIC iX) and Efficia CM Series (Update A)
3 CVE listings
  • CVE-2021-43548 — Improper Input Validation; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2021-43552 — Use of Hard-coded Cryptographic Key; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2021-43550 — Use of a Broken or Risky Cryptographic Algorithm; CVSS v3 5.9; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs36.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-322-01Philips IntelliBridge EC 40 and EC 80 Hub
2 CVE listings
  • CVE-2021-32993 — Use of Hard-coded Credentials; CVSS v3 8.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2021-33017 — Authentication Bypass Using an Alternate Path or Channel; CVSS v3 8.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H; on CISA KEV: no
PhilipsHospital software, apps and device connectivity28.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-313-01Philips MRI 1.5T and 3T (Update A)
3 CVE listings
  • CVE-2021-26262 — Incorrect User Management; CVSS v3 6.2; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2021-26248 — Incorrect Ownership Assignment; CVSS v3 6.2; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2021-42744 — Files or Directories Accessible to External Parties; CVSS v3 6.2; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
PhilipsImaging machines36.20Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-308-01Philips Tasy EMR
2 CVE listings
  • CVE-2021-39375 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'); CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-39376 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'); CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsHospital software, apps and device connectivity28.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-294-01B. Braun Infusomat Space Large Volume Pump (Update A)
5 CVE listings
  • CVE-2021-33886 — Improper Input Validation; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2021-33885 — Insufficient Verification of Data Authenticity; CVSS v3 9.0; vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-33882 — Missing Authentication for Critical Function; CVSS v3 6.8; vector AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N; on CISA KEV: no
  • CVE-2021-33883 — Cleartext Transmission of Sensitive Information; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
  • CVE-2021-33884 — Unrestricted Upload of File with Dangerous Type; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
B. BraunInfusion pumps, medication and supply systems59.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-273-01Boston Scientific Zoom Latitude
5 CVE listings
  • CVE-2021-38400 — Use of Password Hash With Insufficient Computational Effort; CVSS v3 6.9; vector AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2021-38394 — Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques; CVSS v3 6.2; vector AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2021-38392 — Improper Access Control; CVSS v3 6.5; vector AV:P/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2021-38396 — Missing Support for Integrity Check; CVSS v3 6.5; vector AV:P/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2021-38398 — Reliance on Component That is Not Updateable; CVSS v3 6.5; vector AV:P/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L; on CISA KEV: no
Boston ScientificHeart implants, programmers and home monitors56.90Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-215-01Swisslog Healthcare Translogic PTS
8 CVE listings
  • CVE-2021-37163 — Use of Hard-coded Password; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37167 — Execution with Unnecessary Privileges; CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37161 — Integer Underflow (Wrap or Wraparound); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37162 — Integer Underflow (Wrap or Wraparound); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37165 — Integer Underflow (Wrap or Wraparound); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37164 — Out-of-bounds Write; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37166 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-37160 — Download of Code Without Integrity Check; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
Swisslog HealthcareSurgery, therapy, shared parts and other89.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-196-01Ypsomed mylife
4 CVE listings
  • CVE-2021-27491 — Insufficiently Protected Credentials; CVSS v3 5.8; vector AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2021-27495 — Insufficiently Protected Credentials; CVSS v3 6.3; vector AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2021-27499 — Generation of Predictable IV with CBC Mode; CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2021-27503 — Use of Hard-coded Credentials; CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
YpsomedDiabetes devices and apps46.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-187-01Philips Vue PACS (Update C)
17 CVE listings
  • CVE-2020-1938 — Improper Input Validation; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
  • CVE-2018-12326 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-11218 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-4670 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-8014 — Initialization of a Resource with an Insecure Default; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-33020 — Use of a Key Past its Expiration Date; CVSS v3 8.2; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2018-10115 — Improper Initialization; CVSS v3 7.8; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-27501 — Improper Adherence to Coding Standards; CVSS v3 7.5; vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-33018 — Use of a Broken or Risky Cryptographic Algorithm; CVSS v3 6.5; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2021-27497 — Protection Mechanism Failure; CVSS v3 6.5; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
  • CVE-2012-1708 — Data Integrity Issues; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
  • CVE-2015-9251 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 6.1; vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2021-27493 — Improper Neutralization; CVSS v3 6.1; vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2019-9636 — Improper Handling of Unicode Encoding; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2021-33024 — Insufficiently Protected Credentials; CVSS v3 3.7; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2021-33022 — Cleartext Transmission of Sensitive Information; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2021-39369 — Relative Path Traversal; CVSS v3 2.7; vector AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)179.81Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-175-01Philips Interoperability Solution XDS
1 CVE listing
  • CVE-2021-32966 — Cleartext Transmission of Sensitive Information; CVSS v3 3.7; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsHospital software, apps and device connectivity13.70Device maker onlyCISA advisory2026-10-09
ICSMA-21-161-01ZOLL Defibrillator Dashboard
6 CVE listings
  • CVE-2021-27489 — Unrestricted Upload of File with Dangerous Type; CVSS v3 9.9; vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2021-27481 — Use of Hard-coded Cryptographic Key; CVSS v3 7.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2021-27487 — Cleartext Storage of Sensitive Information; CVSS v3 7.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2021-27479 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 4.6; vector AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2021-27485 — Storing Passwords in a Recoverable Format; CVSS v3 7.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2021-27483 — Improper Privilege Management; CVSS v3 5.3; vector AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
ZOLLHospital software, apps and device connectivity69.90Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-152-01Hillrom Medical Device Management (Update C)
2 CVE listings
  • CVE-2021-27410 — Out-of-bounds Write; CVSS v3 5.9; vector AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2021-27408 — Out-of-bounds Read; CVSS v3 5.9; vector AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
HillromPatient monitors, ECG and vital signs25.90Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-084-01Philips Gemini PET/CT Family
1 CVE listing
  • CVE-2021-27456 — Storage of Sensitive Data in a Mechanism without Access Control; CVSS v3 2.4; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsImaging machines12.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-047-01Hamilton-T1
3 CVE listings
  • CVE-2020-27278 — Use of Hard-coded Credentials; CVSS v3 3.5; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2020-27282 — Missing XML Validation; CVSS v3 4.3; vector AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2020-27290 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 2.1; vector AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
Hamilton MedicalBreathing, sleep and anesthesia34.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-019-01Philips Interventional Workstations
1 CVE listing
  • CVE-2020-27298 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'); CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
PhilipsImaging machines16.50Device maker onlyCISA advisory2026-10-09
ICSMA-21-012-01SOOIL Dana Diabecare RS Products
9 CVE listings
  • CVE-2020-27256 — Use of Hard-coded Credentials; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
  • CVE-2020-27258 — Insufficiently Protected Credentials; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-27264 — Use of Insufficiently Random Values; CVSS v3 7.6; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2020-27266 — Use of Client-Side Authentication; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-27268 — Client-Side Enforcement of Server-Side Security; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-27269 — Authentication Bypass by Capture-replay; CVSS v3 5.4; vector AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N; on CISA KEV: no
  • CVE-2020-27270 — Unprotected Transport of Credentials; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-27272 — Key Exchange without Entity Authentication; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-27276 — Authentication Bypass by Spoofing; CVSS v3 5.7; vector AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
SOOIL DevelopmentsDiabetes devices and apps97.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-21-007-01Innokas Yhtymä Oy Vital Signs Monitor
2 CVE listings
  • CVE-2020-27262 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 4.6; vector AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2020-27260 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'); CVSS v3 5.3; vector AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N; on CISA KEV: no
Innokas Yhtymä OyPatient monitors, ECG and vital signs25.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-345-01Medtronic MyCareLink Smart
3 CVE listings
  • CVE-2020-25183 — Improper Authentication; CVSS v3 8.0; vector AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-25187 — Heap-based Buffer Overflow; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-27252 — Time-of-check Time-of-use (TOCTOU) Race Condition; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors38.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-343-01GE Healthcare Imaging and Ultrasound Products
2 CVE listings
  • CVE-2020-25175 — Unprotected Transport of Credentials; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-25179 — Exposure of Sensitive System Information to an Unauthorized Control Sphere; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
GE HealthCareImaging machines29.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-317-01BD Alaris 8015 PC Unit and BD Alaris Systems Manager
1 CVE listing
  • CVE-2020-25165 — Improper Authentication; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
BDInfusion pumps, medication and supply systems16.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-296-02B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus (Update A)
11 CVE listings
  • CVE-2020-25158 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 7.6; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2020-25154 — URL Redirection to Untrusted Site ('Open Redirect'); CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2020-25162 — Improper Neutralization of Data within XPath Expressions ('XPath Injection'); CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-25152 — Session Fixation; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-25164 — Use of a One-Way Hash without a Salt; CVSS v3 5.1; vector AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-25150 — Relative Path Traversal; CVSS v3 7.6; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2020-25166 — Improper Verification of Cryptographic Signature; CVSS v3 6.8; vector AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2020-16238 — Improper Privilege Management; CVSS v3 6.7; vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-25168 — Use of Hard-coded Credentials; CVSS v3 3.3; vector AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2020-25156 — Active Debug Code; CVSS v3 7.2; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-25160 — Improper Access Control; CVSS v3 6.8; vector AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L; on CISA KEV: no
B. BraunInfusion pumps, medication and supply systems117.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-296-01B. Braun OnlineSuite
3 CVE listings
  • CVE-2020-25172 — Relative Path Traversal; CVSS v3 8.6; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
  • CVE-2020-25174 — Uncontrolled Search Path Element; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-25170 — Improper Neutralization of Formula Elements in a CSV File; CVSS v3 6.9; vector AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N; on CISA KEV: no
B. BraunInfusion pumps, medication and supply systems38.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-261-01Philips Clinical Collaboration Platform
5 CVE listings
  • CVE-2020-14506 — Cross-Site Request Forgery (CSRF); CVSS v3 3.4; vector AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2020-14525 — Improper Neutralization of Script in Attributes in a Web Page; CVSS v3 3.5; vector AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2020-16198 — Protection Mechanism Failure; CVSS v3 5.0; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-16200 — Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade'); CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2020-16247 — Configuration; CVSS v3 6.8; vector AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)56.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-254-01Philips Patient Monitoring Devices (Update C)
8 CVE listings
  • CVE-2020-16214 — Improper Neutralization of Formula Elements in a CSV File; CVSS v3 4.2; vector AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2020-16218 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 3.5; vector AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2020-16222 — Improper Authentication; CVSS v3 5.0; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-16228 — Improper Check for Certificate Revocation; CVSS v3 6.0; vector AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2020-16224 — Improper Handling of Length Parameter Inconsistency; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2020-16220 — Improper Validation of Syntactic Correctness of Input; CVSS v3 3.5; vector AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L; on CISA KEV: no
  • CVE-2020-16216 — Improper Input Validation; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2020-16212 — Exposure of Resource to Wrong Sphere; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs86.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-233-01Philips SureSigns VS4
3 CVE listings
  • CVE-2020-16237 — Improper Input Validation; CVSS v3 2.1; vector AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L; on CISA KEV: no
  • CVE-2020-16241 — Improper Access Control; CVSS v3 6.3; vector AV:P/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H; on CISA KEV: no
  • CVE-2020-16239 — Improper Authentication; CVSS v3 4.9; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs36.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-212-01Philips DreamMapper
1 CVE listing
  • CVE-2020-14518 — Insertion of Sensitive Information into Log File; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsBreathing, sleep and anesthesia15.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-196-01Capsule Technologies SmartLinx Neuron 2 (Update A)
1 CVE listing
  • CVE-2019-5024 — Protection Mechanism Failure; CVSS v3 7.6; vector AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
Capsule TechnologiesHospital software, apps and device connectivity17.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-184-01OpenClinic GA (Update B)
14 CVE listings
  • CVE-2020-14485 — Authentication Bypass Using an Alternate Path or Channel; CVSS v3 9.4; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2020-14484 — Improper Restriction of Excessive Authentication Attempts; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-14494 — Improper Authentication; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-14491 — Missing Authorization; CVSS v3 8.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
  • CVE-2020-14493 — Execution with Unnecessary Privileges; CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-14488 — Unrestricted Upload of File with Dangerous Type; CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-14490 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CVSS v3 8.8; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-14486 — Improper Authorization; CVSS v3 6.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-14492 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2014-0114 — Use of Unmaintained Third Party Components; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2016-1181 — Use of Unmaintained Third Party Components; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2016-1182 — Use of Unmaintained Third Party Components; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-14489 — Insufficiently Protected Credentials; CVSS v3 6.2; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-14487 — Hidden Functionality; CVSS v3 9.4; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
OpenClinic GA (open source)Hospital software, apps and device connectivity149.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-177-01Philips Ultrasound Systems
1 CVE listing
  • CVE-2020-14477 — Authentication Bypass Using an Alternate Path or Channel; CVSS v3 3.6; vector AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
PhilipsImaging machines13.60Device maker onlyCISA advisory2026-10-09
ICSMA-20-170-06BD Alaris PCU (Update A)
1 CVE listing
  • CVE-2019-11479 — Uncontrolled Resource Consumption; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L; on CISA KEV: no
BDInfusion pumps, medication and supply systems15.30Device maker onlyCISA advisory2026-10-09
ICSMA-20-170-05BIOTRONIK CardioMessenger II
5 CVE listings
  • CVE-2019-18246 — Improper Authentication; CVSS v3 4.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2019-18248 — Cleartext Transmission of Sensitive Information; CVSS v3 4.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2019-18252 — Improper Authentication; CVSS v3 4.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2019-18254 — Missing Encryption of Sensitive Data; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2019-18256 — Storing Passwords in a Recoverable Format; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
BIOTRONIKHeart implants, programmers and home monitors54.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-170-04Baxter Sigma Spectrum Infusion Pumps (Update B)
6 CVE listings
  • CVE-2020-12039 — Use of Hard-coded Password; CVSS v3 4.3; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-12040 — Cleartext Transmission of Sensitive Information; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-12045 — Use of Hard-coded Password; CVSS v3 8.6; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H; on CISA KEV: no
  • CVE-2020-12041 — Incorrect Permission Assignment for Critical Resource; CVSS v3 8.6; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H; on CISA KEV: no
  • CVE-2020-12047 — Use of Hard-coded Password; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2020-12043 — Operation on a Resource after Expiration or Release; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
BaxterInfusion pumps, medication and supply systems68.60Device maker onlyCISA advisory2026-10-09
ICSMA-20-170-03Baxter Phoenix Hemodialysis Delivery System (Update A)
1 CVE listing
  • CVE-2020-12048 — Cleartext Transmission of Sensitive Information; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
BaxterSurgery, therapy, shared parts and other17.50Device maker onlyCISA advisory2026-10-09
ICSMA-20-170-02Baxter PrismaFlex and PrisMax (Update B)
3 CVE listings
  • CVE-2020-12036 — Cleartext Transmission of Sensitive Information; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-12035 — Improper Authentication; CVSS v3 7.6; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2020-12037 — Use of Hard-coded Password; CVSS v3 5.4; vector AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L; on CISA KEV: no
BaxterSurgery, therapy, shared parts and other37.60Device maker onlyCISA advisory2026-10-09
ICSMA-20-170-01Baxter ExactaMix (Update A)
7 CVE listings
  • CVE-2020-12016 — Use of Hard-coded Password; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-12012 — Use of Hard-coded Password; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-12008 — Cleartext Transmission of Sensitive Information; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2020-12032 — Missing Encryption of Sensitive Data; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-12024 — Improper Access Control; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-12020 — Exposure of Resource to Wrong Sphere; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H; on CISA KEV: no
  • CVE-2017-0143 — Improper Input Validation; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
BaxterInfusion pumps, medication and supply systems78.11Device maker onlyCISA advisory2026-10-09
ICSMA-20-163-01Philips IntelliBridge Enterprise IBE
1 CVE listing
  • CVE-2020-12023 — Insertion of Sensitive Information into Log File; CVSS v3 2.0; vector AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsHospital software, apps and device connectivity12.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-091-01BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System
1 CVE listing
  • CVE-2020-10598 — Protection Mechanism Failure; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems16.80Device maker onlyCISA advisory2026-10-09
ICSMA-20-079-01Insulet Omnipod
1 CVE listing
  • CVE-2020-10627 — Improper Access Control; CVSS v3 7.3; vector AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
InsuletDiabetes devices and apps17.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-049-02GE Healthcare Ultrasound Products (Update A)
2 CVE listings
  • CVE-2020-6977 — Protection Mechanism Failure; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2024-1486 — Incorrect User Management; CVSS v3 7.4; vector AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
GE HealthCareImaging machines28.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-049-01Spacelabs Xhibit Telemetry Receiver (XTR)
1 CVE listing
  • CVE-2019-0708 — Improper Input Validation; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
SpacelabsPatient monitors, ECG and vital signs19.81Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-20-023-01GE CARESCAPE, ApexPro, and Clinical Information Center systems
6 CVE listings
  • CVE-2020-6961 — Plaintext Storage of a Password; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-6962 — Improper Input Validation; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-6963 — Use of Hard-coded Credentials; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-6964 — Missing Authentication for Critical Function; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-6965 — Unrestricted Upload of File with Dangerous Type; CVSS v3 8.5; vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2020-6966 — Inadequate Encryption Strength; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
GE HealthCarePatient monitors, ECG and vital signs610.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-353-01Philips Veradius Unity, Pulsera, and Endura Dual WAN Routers
1 CVE listing
  • CVE-2019-18263 — Inadequate Encryption Strength; CVSS v3 5.3; vector AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
PhilipsImaging machines15.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-318-01Philips IntelliBridge EC40/80 (Update A)
1 CVE listing
  • CVE-2019-18241 — Inadequate Encryption Strength; CVSS v3 6.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
PhilipsHospital software, apps and device connectivity16.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-311-02Medtronic Valleylab FT10 and FX8
4 CVE listings
  • CVE-2019-13543 — Use of Hard-coded Credentials; CVSS v3 5.8; vector AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2019-13539 — Use of Weak Hash; CVSS v3 7.0; vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-3464 — Improper Input Validation; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-3463 — Improper Input Validation; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
MedtronicSurgery, therapy, shared parts and other49.80Device maker onlyCISA advisory2026-10-09
ICSMA-19-311-01Medtronic Valleylab FT10 and LS10
2 CVE listings
  • CVE-2019-13531 — Improper Authentication; CVSS v3 4.8; vector AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L; on CISA KEV: no
  • CVE-2019-13535 — Protection Mechanism Failure; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
MedtronicSurgery, therapy, shared parts and other24.80Device maker onlyCISA advisory2026-10-09
ICSMA-19-297-01Philips IntelliSpace Perinatal
1 CVE listing
  • CVE-2019-13546 — Exposure of Resource to Wrong Sphere; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs16.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-274-01Interpeak IPnet TCP/IP Stack (Update D)
11 CVE listings
  • CVE-2019-12256 — Stack-based Buffer Overflow; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12257 — Heap-based Buffer Overflow; CVSS v3 8.8; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12255 — Integer Underflow (Wrap or Wraparound); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12260 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12261 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 8.8; vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12263 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'); CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-12258 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'); CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2019-12264 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'); CVSS v3 7.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H; on CISA KEV: no
  • CVE-2019-12259 — NULL Pointer Dereference; CVSS v3 6.3; vector AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H; on CISA KEV: no
  • CVE-2019-12262 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'); CVSS v3 7.1; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H; on CISA KEV: no
  • CVE-2019-12265 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'); CVSS v3 5.4; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L; on CISA KEV: no
Interpeak (IPnet; multiple RTOS vendors)Surgery, therapy, shared parts and other119.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-255-01Philips IntelliVue WLAN
2 CVE listings
  • CVE-2019-13530 — Use of Hard-coded Password; CVSS v3 6.4; vector AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2019-13534 — Download of Code Without Integrity Check; CVSS v3 6.4; vector AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs26.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-248-01BD Pyxis (Update A)
1 CVE listing
  • CVE-2019-13517 — Session Fixation; CVSS v3 7.6; vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L; on CISA KEV: no
BDInfusion pumps, medication and supply systems17.60Device maker onlyCISA advisory2026-10-09
ICSMA-19-241-02Philips HDI 4000 Ultrasound
1 CVE listing
  • CVE-2019-10988 — Use of Obsolete Function; CVSS v3 3.0; vector AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
PhilipsImaging machines13.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-241-01Change Healthcare McKesson and Horizon Cardiology
1 CVE listing
  • CVE-2018-18630 — Incorrect Default Permissions; CVSS v3 7.8; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
Change HealthcareImaging software (PACS and DICOM)17.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-192-01Philips Holter 2010 Plus
1 CVE listing
  • CVE-2019-10968 — Use of Obsolete Function; CVSS v3 1.9; vector AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs11.90Device maker onlyCISA advisory2026-10-09
ICSMA-19-190-01GE Aestiva and Aespire Anesthesia (Update A)
1 CVE listing
  • CVE-2019-10966 — Improper Authentication; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
GE HealthCareBreathing, sleep and anesthesia15.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-178-01Medtronic MiniMed 508 and Paradigm Series Insulin Pumps
1 CVE listing
  • CVE-2019-10964 — Improper Access Control; CVSS v3 7.1; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
MedtronicDiabetes devices and apps17.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-164-01BD Alaris Gateway Workstation
2 CVE listings
  • CVE-2019-10962 — Improper Access Control; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2019-10959 — Unrestricted Upload of File with Dangerous Type; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems210.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-120-01Philips Tasy EMR (Update A)
2 CVE listings
  • CVE-2019-6562 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CVSS v3 4.1; vector AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2019-13557 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 4.3; vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsHospital software, apps and device connectivity24.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-113-01Fujifilm FCR Capsula X/Carbon X
2 CVE listings
  • CVE-2019-10948 — Uncontrolled Resource Consumption; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2019-10950 — Improper Access Control; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
FujifilmImaging machines29.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-080-01Medtronic Conexus Radio Frequency Telemetry Protocol (Update C)
2 CVE listings
  • CVE-2019-6538 — Improper Access Control; CVSS v3 9.3; vector AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2019-6540 — Cleartext Transmission of Sensitive Information; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors29.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-029-02BD FACSLyric (Update A)
1 CVE listing
  • CVE-2019-6517 — Improper Access Control; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDLab and diagnostic instruments16.80Device maker onlyCISA advisory2026-10-09
ICSMA-19-029-01Stryker Medical Beds
9 CVE listings
  • CVE-2017-13077 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13078 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13079 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13080 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13081 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13082 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13086 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13087 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13088 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
StrykerSurgery, therapy, shared parts and other96.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-19-022-01Dräger Infinity Delta
3 CVE listings
  • CVE-2018-19010 — Improper Input Validation; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2018-19014 — Insertion of Sensitive Information into Log File; CVSS v3 4.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2018-19012 — Improper Privilege Management; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
DrägerPatient monitors, ECG and vital signs38.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-347-01Medtronic 9790, 2090 CareLink, and 29901 Encore Programmers
1 CVE listing
  • CVE-2018-18984 — Missing Encryption of Sensitive Data; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors14.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-340-01Philips HealthSuite Health Android App
1 CVE listing
  • CVE-2018-19001 — Inadequate Encryption Strength; CVSS v3 3.5; vector AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
PhilipsHospital software, apps and device connectivity13.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-312-01Philips iSite and IntelliSpace PACS
1 CVE listing
  • CVE-2018-17906 — Weak Password Requirements; CVSS v3 6.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)16.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-310-01Roche Diagnostics Point of Care Handheld Medical Devices (Update A)
5 CVE listings
  • CVE-2018-18561 — Improper Authentication; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-18562 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'); CVSS v3 8.0; vector AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2018-18563 — Unrestricted Upload of File with Dangerous Type; CVSS v3 8.0; vector AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2018-18564 — Improper Access Control; CVSS v3 8.3; vector AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-18565 — Improper Access Control; CVSS v3 8.2; vector AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H; on CISA KEV: no
Roche DiagnosticsLab and diagnostic instruments58.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-277-02Change Healthcare PeerVue Web Server
1 CVE listing
  • CVE-2018-10624 — Generation of Error Message Containing Sensitive Information; CVSS v3 4.3; vector AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
Change HealthcareImaging software (PACS and DICOM)14.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-277-01Carestream Vue RIS
1 CVE listing
  • CVE-2018-17891 — Generation of Error Message Containing Sensitive Information; CVSS v3 3.7; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
CarestreamImaging software (PACS and DICOM)13.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-240-01Qualcomm Life Capsule
1 CVE listing
  • CVE-2014-9222 — DEPRECATED: Code; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
Qualcomm LifeHospital software, apps and device connectivity19.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-235-01BD Alaris Plus
1 CVE listing
  • CVE-2018-14786 — Improper Authentication; CVSS v3 9.4; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems19.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-233-01Philips IntelliVue Information Center iX (Update B)
1 CVE listing
  • CVE-1999-0103 — Uncontrolled Resource Consumption; CVSS v3 5.7; vector AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs15.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-228-01Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs (Update A)
2 CVE listings
  • CVE-2018-14799 — Improper Input Validation; CVSS v3 5.9; vector AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2018-14801 — Use of Hard-coded Credentials; CVSS v3 6.1; vector AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs26.10Device maker onlyCISA advisory2026-10-09
ICSMA-18-226-01Philips IntelliSpace Cardiovascular Vulnerabilities
2 CVE listings
  • CVE-2018-14787 — Improper Privilege Management; CVSS v3 7.3; vector AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H; on CISA KEV: no
  • CVE-2018-14789 — Unquoted Search Path or Element; CVSS v3 4.2; vector AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)27.30Device maker onlyCISA advisory2026-10-09
ICSMA-18-219-02Medtronic MiniMed MMT-500/MMT-503 Remote Controllers (Update A)
2 CVE listings
  • CVE-2018-10634 — Cleartext Transmission of Sensitive Information; CVSS v3 4.8; vector AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-14781 — Authentication Bypass by Capture-replay; CVSS v3 5.3; vector AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N; on CISA KEV: no
MedtronicDiabetes devices and apps25.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-219-01Medtronic MyCareLink 24950 Patient Monitor (Update A)
2 CVE listings
  • CVE-2018-10626 — Insufficient Verification of Data Authenticity; CVSS v3 4.4; vector AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2018-10622 — Cleartext Storage in a File or on Disk; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors26.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-179-01Medtronic MyCareLink Patient Monitor
2 CVE listings
  • CVE-2018-8870 — Use of Hard-coded Password; CVSS v3 6.4; vector AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-8868 — Exposed Dangerous Method or Function; CVSS v3 6.2; vector AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors26.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-165-01Natus Xltek NeuroWorks
8 CVE listings
  • CVE-2017-2852 — Out-of-bounds Read; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-2853 — Stack-based Buffer Overflow; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-2858 — Out-of-bounds Read; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-2860 — Out-of-bounds Read; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-2861 — Out-of-bounds Read; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-2867 — Stack-based Buffer Overflow; CVSS v3 9.0; vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-2868 — Stack-based Buffer Overflow; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-2869 — Stack-based Buffer Overflow; CVSS v3 10.0; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
Natus MedicalSurgery, therapy, shared parts and other810.00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-156-01Philips' IntelliVue Patient and Avalon Fetal Monitors
3 CVE listings
  • CVE-2018-10597 — Improper Authentication; CVSS v3 8.3; vector AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-10599 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 6.4; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2018-10601 — Stack-based Buffer Overflow; CVSS v3 8.2; vector AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs38.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-144-01BeaconMedaes TotalAlert Scroll Medical Air Systems
3 CVE listings
  • CVE-2018-7526 — Improper Access Control; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2018-7518 — Insufficiently Protected Credentials; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-7510 — Plaintext Storage of a Password; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
BeaconMedaesSurgery, therapy, shared parts and other37.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-142-01BD Kiestra and InoquIA Systems (Update A)
2 CVE listings
  • CVE-2018-10593 — Product UI does not Warn User of Unsafe Actions; CVSS v3 5.6; vector AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H; on CISA KEV: no
  • CVE-2018-10595 — Product UI does not Warn User of Unsafe Actions; CVSS v3 6.3; vector AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
BDLab and diagnostic instruments26.30Device maker onlyCISA advisory2026-10-09
ICSMA-18-137-02Philips EncoreAnywhere
1 CVE listing
  • CVE-2018-8863 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
PhilipsBreathing, sleep and anesthesia15.90Device maker onlyCISA advisory2026-10-09
ICSMA-18-137-01Medtronic N'Vision Clinician Programmer (Update A)
2 CVE listings
  • CVE-2018-8849 — Missing Encryption of Sensitive Data; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-10631 — Protection Mechanism Failure; CVSS v3 6.3; vector AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MedtronicSurgery, therapy, shared parts and other26.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-128-01Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update B)
2 CVE listings
  • CVE-2018-6020 — Improper Authentication; CVSS v3 6.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
  • CVE-2018-6021 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'); CVSS v3 7.4; vector AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L; on CISA KEV: no
GE HealthCareSurgery, therapy, shared parts and other27.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-123-01Philips Brilliance Computed Tomography (CT) System (Update A)
3 CVE listings
  • CVE-2018-8853 — Execution with Unnecessary Privileges; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2018-8861 — Exposure of Resource to Wrong Sphere; CVSS v3 6.1; vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L; on CISA KEV: no
  • CVE-2018-8857 — Use of Hard-coded Credentials; CVSS v3 8.4; vector AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsImaging machines38.40Device maker onlyCISA advisory2026-10-09
ICSMA-18-114-01BD Pyxis
9 CVE listings
  • CVE-2017-13077 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13078 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13079 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13080 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13081 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13082 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13086 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13087 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
  • CVE-2017-13088 — Reusing a Nonce, Key Pair in Encryption; CVSS v3 6.8; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N; on CISA KEV: no
BDInfusion pumps, medication and supply systems96.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-107-02Biosense Webster Carto 3 System VulnerabilitiesBiosense WebsterSurgery, therapy, shared parts and other00Device maker onlyCISA advisory2026-10-09
ICSMA-18-107-01Abbott Laboratories Defibrillator
2 CVE listings
  • CVE-2017-12712 — Improper Authentication; CVSS v3 7.5; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12714 — Improper Restriction of Power Consumption; CVSS v3 5.3; vector AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
AbbottHeart implants, programmers and home monitors27.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-088-01Philips iSite/IntelliSpace PACS Vulnerabilities (Update A)PhilipsImaging software (PACS and DICOM)00Device maker onlyCISA advisory2026-10-09
ICSMA-18-086-01Philips Alice 6 Vulnerabilities (Update B)
2 CVE listings
  • CVE-2018-5451 — Improper Authentication; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
  • CVE-2018-7498 — Missing Encryption of Sensitive Data; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
PhilipsBreathing, sleep and anesthesia25.30Device maker onlyCISA advisory2026-10-09
ICSMA-18-058-02Philips Intellispace Portal ISP Vulnerabilities
35 CVE listings
  • CVE-2018-5474 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0143 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2017-0144 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2017-0145 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2017-0146 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2017-0148 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2017-0272 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0277 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0278 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0279 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0269 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0273 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0280 — Improper Input Validation; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0147 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: yes
  • CVE-2017-0267 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0268 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0270 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0271 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0274 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0275 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-0276 — Exposure of Sensitive Information to an Unauthorized Actor; CVSS v3 5.9; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-5472 — Permissions, Privileges, and Access Controls; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2018-5468 — Permissions, Privileges, and Access Controls; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2017-0199 — Permissions, Privileges, and Access Controls; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: yes
  • CVE-2005-1794 — Permissions, Privileges, and Access Controls; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2018-5470 — Unquoted Search Path or Element; CVSS v3 7.8; vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2018-5454 — Active Debug Code; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N; on CISA KEV: no
  • CVE-2018-5458 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2018-5462 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2018-5464 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2018-5466 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2011-3389 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2004-2761 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2014-3566 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
  • CVE-2016-2183 — Cryptographic Issues; CVSS v3 Score range only on CISA page; no single score; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)357.87Device maker onlyCISA advisory2026-10-09
ICSMA-18-058-01Medtronic 2090 Carelink Programmer Vulnerabilities (Update C)
3 CVE listings
  • CVE-2018-5446 — Storing Passwords in a Recoverable Format; CVSS v3 4.9; vector AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-5448 — Relative Path Traversal; CVSS v3 4.8; vector AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2018-10596 — Improper Restriction of Communication Channel to Intended Endpoints; CVSS v3 7.1; vector AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
MedtronicHeart implants, programmers and home monitors37.10Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-037-02GE Medical Devices Vulnerability
23 CVE listings
  • CVE-2010-5306 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2009-5143 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2013-7404 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2014-7232 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2010-5310 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2014-7233 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2012-6693 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2012-6694 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2012-6695 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2013-7442 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-14008 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2011-5322 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2007-6757 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2003-1603 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2001-1594 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2010-5309 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2010-5307 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-14004 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2004-2777 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-14002 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2002-2446 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2012-6660 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-14006 — Improper Authentication; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
GE HealthCareImaging machines239.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-037-01Vyaire Medical CareFusion Upgrade Utility Vulnerability
1 CVE listing
  • CVE-2018-5457 — Uncontrolled Search Path Element; CVSS v3 6.7; vector AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
Vyaire MedicalBreathing, sleep and anesthesia16.70Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-18-025-01Philips IntelliSpace Cardiovascular System Vulnerability
1 CVE listing
  • CVE-2018-5438 — Insufficient Session Expiration; CVSS v3 6.7; vector AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)16.70Device maker onlyCISA advisory2026-10-09
ICSMA-17-332-01Ethicon Endo-Surgery Generator G11 Vulnerability
1 CVE listing
  • CVE-2017-14018 — Improper Authentication; CVSS v3 4.8; vector AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L; on CISA KEV: no
Ethicon Endo-SurgerySurgery, therapy, shared parts and other14.80Device maker onlyCISA advisory2026-10-09
ICSMA-17-318-01Philips IntelliSpace Cardiovascular System and Xcelera System Vulnerability
1 CVE listing
  • CVE-2017-14111 — Insufficiently Protected Credentials; CVSS v3 7.2; vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)17.20Device maker onlyCISA advisory2026-10-09
ICSMA-17-292-01Boston Scientific ZOOM LATITUDE PRM Vulnerabilities
2 CVE listings
  • CVE-2017-14014 — Use of Hard-coded Cryptographic Key; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-14012 — Missing Encryption of Sensitive Data; CVSS v3 4.6; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
Boston ScientificHeart implants, programmers and home monitors24.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-255-01Philips' IntelliView MX40 Patient Worn Monitor (WLAN) Vulnerabilities
2 CVE listings
  • CVE-2017-9657 — Improper Cleanup on Thrown Exception; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-9658 — Improper Handling of Exceptional Conditions; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
PhilipsPatient monitors, ECG and vital signs26.50Device maker onlyCISA advisory2026-10-09
ICSMA-17-250-02ASmiths Medical Medfusion 4000 Wireless Syringe Infusion Pump Vulnerabilities (Update A)
8 CVE listings
  • CVE-2017-12718 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'); CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12722 — Out-of-bounds Read; CVSS v3 5.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L; on CISA KEV: no
  • CVE-2017-12725 — Use of Hard-coded Credentials; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12720 — Improper Access Control; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12724 — Use of Hard-coded Credentials; CVSS v3 8.1; vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12726 — Use of Hard-coded Password; CVSS v3 5.6; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
  • CVE-2017-12721 — Improper Certificate Validation; CVSS v3 7.5; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2017-12723 — Password in Configuration File; CVSS v3 3.7; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
Smiths MedicalInfusion pumps, medication and supply systems89.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-250-01i-SENS, Inc. SmartLog Diabetes Management Software
1 CVE listing
  • CVE-2017-13993 — Unquoted Search Path or Element; CVSS v3 7.3; vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H; on CISA KEV: no
i-SENSDiabetes devices and apps17.30Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-241-01Abbott Laboratories’ Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI Pacemaker Vulnerabilities
3 CVE listings
  • CVE-2017-12712 — Improper Authentication; CVSS v3 7.5; vector AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-12714 — Improper Restriction of Power Consumption; CVSS v3 5.3; vector AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H; on CISA KEV: no
  • CVE-2017-12716 — Missing Encryption of Sensitive Data; CVSS v3 3.1; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N; on CISA KEV: no
AbbottHeart implants, programmers and home monitors37.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-229-01Philips' DoseWise Portal Vulnerabilities
2 CVE listings
  • CVE-2017-9656 — Use of Hard-coded Credentials; CVSS v3 9.1; vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2017-9654 — Cleartext Storage of Sensitive Information; CVSS v3 6.5; vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
PhilipsImaging software (PACS and DICOM)29.10Device maker onlyCISA advisory2026-10-09
ICSMA-17-227-01BMC Medical and 3B Medical Luna CPAP Machine
1 CVE listing
  • CVE-2017-12701 — Improper Input Validation; CVSS v3 4.6; vector AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L; on CISA KEV: no
BMC Medical / 3B MedicalBreathing, sleep and anesthesia14.60Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-215-02Siemens Molecular Imaging Vulnerabilities
4 CVE listings
  • CVE-2015-1635 — Improper Control of Generation of Code ('Code Injection'); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
  • CVE-2015-1497 — Improper Control of Generation of Code ('Code Injection'); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2015-7860 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2015-7861 — Permissions, Privileges, and Access Controls; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
SiemensImaging machines49.81Device maker onlyCISA advisory2026-10-09
ICSMA-17-215-01Siemens Molecular Imaging Vulnerabilities
2 CVE listings
  • CVE-2008-4250 — Improper Control of Generation of Code ('Code Injection'); CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
  • CVE-2017-7269 — Improper Restriction of Operations within the Bounds of a Memory Buffer; CVSS v3 9.8; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: yes
SiemensImaging machines29.82Device maker onlyCISA advisory2026-10-09
ICSMA-17-082-02B. Braun Medical SpaceCom Open Redirect Vulnerability
1 CVE listing
  • CVE-2017-6018 — URL Redirection to Untrusted Site ('Open Redirect'); CVSS v3 5.4; vector AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N; on CISA KEV: no
B. BraunInfusion pumps, medication and supply systems15.40Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-082-01BD Kiestra PerformA and KLA Journal Service Applications Hard-Coded Passwords Vulnerability
1 CVE listing
  • CVE-2017-6022 — Use of Hard-coded Password; CVSS v3 7.3; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L; on CISA KEV: no
BDLab and diagnostic instruments17.30Device maker onlyCISA advisory2026-10-09
ICSMA-17-017-02BD Alaris 8015 PC Unit (Update B)
2 CVE listings
  • CVE-2016-8375 — Insufficiently Protected Credentials; CVSS v3 4.9; vector AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2016-9355 — 7PK - Security Features; CVSS v3 6.8; vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; on CISA KEV: no
BDInfusion pumps, medication and supply systems26.80Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-17-017-01BD Alaris 8000 Insufficiently Protected Credentials Vulnerability
1 CVE listing
  • CVE-2016-8375 — Insufficiently Protected Credentials; CVSS v3 4.9; vector AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N; on CISA KEV: no
BDInfusion pumps, medication and supply systems14.90Device maker onlyCISA advisory2026-10-09
ICSMA-17-009-01ASt. Jude Merlin@home Transmitter Vulnerability (Update A)
1 CVE listing
  • CVE-2017-5149 — Channel Accessible by Non-Endpoint; CVSS v3 8.9; vector AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H; on CISA KEV: no
St. Jude MedicalHeart implants, programmers and home monitors18.90Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-16-306-01Smiths Medical CADD-Solis Medication Safety Software Vulnerabilities
2 CVE listings
  • CVE-2016-8355 — Incorrect Permission Assignment for Critical Resource; CVSS v3 9.9; vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
  • CVE-2016-8358 — Channel Accessible by Non-Endpoint; CVSS v3 8.5; vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H; on CISA KEV: no
Smiths MedicalInfusion pumps, medication and supply systems29.90Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-16-279-01Animas OneTouch Ping Insulin Pump Vulnerabilities
3 CVE listings
  • CVE-2016-5084 — Cleartext Transmission of Sensitive Information; CVSS v3 6.5; vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; on CISA KEV: no
  • CVE-2016-5085 — Use of Insufficiently Random Values; CVSS v3 4.2; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N; on CISA KEV: no
  • CVE-2016-5086 — Authentication Bypass by Capture-replay; CVSS v3 6.4; vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L; on CISA KEV: no
AnimasDiabetes devices and apps36.50Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-16-196-01Philips Xper-IM Connect VulnerabilitiesPhilipsHospital software, apps and device connectivity00Outside or anonymous reporter creditedCISA advisory2026-10-09
ICSMA-16-089-01CareFusion Pyxis SupplyStation System VulnerabilitiesBDInfusion pumps, medication and supply systems00Outside or anonymous reporter creditedCISA advisory2026-10-09

Source: The CISA advisory source URL and check date appear in each row.

Where do the numbers everyone quotes come from?

Mostly from security companies, not from the government. The best-known figure, "6.2 vulnerabilities per medical device", traces to a February 7, 2018 vendor blog post with no sample, dates or method. The FBI printed it in 2022 without naming the research firm.

The numbers people repeat, and where each one started

Where do the numbers everyone quotes come from?
The numberWhat the original saysWho said it first, and whenWhat it really countsSafe to quote?
"6.2 vulnerabilities per medical device""Sensato has found an average of 6.2 vulnerabilities per medical device."Sensato blog post, February 7, 2018 (earliest we found)The post gives no sample, observation dates or method.No
"53% of connected medical devices have a known critical vulnerability""53% of connected medical devices and other IoT devices in hospitals have a known critical vulnerability."Cynerio press release, January 19, 2022Medical devices and other connected devices, at Cynerio's own customersOnly with Cynerio's name, the year and "and other IoT devices"
"More than 40% of medical devices are end-of-life"The 2018 post says "60 percent of devices are at end-of-life stage."MedTech Dive, December 1, 2021, crediting Sensato; then the FBI in 2022The cited versions say 60% and more than 40%. Those claims can both be true, but neither gives a sampling method.No
"75% of infusion pumps are vulnerable"75% of more than 200,000 pumps "had known security gaps", meaning a known vulnerability "and/or" another security alertUnit 42, Palo Alto Networks, March 2, 2022Pumps with a vulnerability or an alert. Not only CVEs.Yes, as "known security gaps" in Unit 42's March 2022 report and pump sample
"99% of hospitals have devices with exploited flaws""9% of IoMT devices contain confirmed KEVs in their systems, impacting 99% of organizations."Claroty, March 26, 202599% is organizations (of 351). The device share is 9%.Yes, with Claroty, its March 2025 report, sample and unit
"993 medical device vulnerabilities""993 vulnerabilities were found in 2023 (a 59% increase from 2022) spanning 966 healthcare products"Health-ISAC, Finite State and Securin, 2023Products from 117 vendors, including healthcare software. The report says software applications hold 64%.Yes, as the report's 2023 healthcare-product findings; not 993 newly disclosed device CVEs

Source: each linked original, checked October 9, 2026 (UTC). Quoted words are copied from those sources; the rest of the table explains their scope.

Here is where "6.2" appears. A 2018 vendor blog post. A 2021 trade article that names Sensato. A 2022 FBI notice that calls it "a research report in 2021" by "a cybersecurity firm" and names no one. A 2023 GAO report that cites the FBI. The FBI does not identify its 2021 source, so we cannot prove that step in the chain. The same vendor figure now reads like a government fact.

Why do the numbers disagree so much?

Because they answer three different questions. One counts flaws, one counts devices, and one counts attacks.

Three questions, three kinds of answer

Why do the numbers disagree so much?
The questionWho can answer itA real answer
How many flaws have been found?CISA's advisories536, in 192 advisories (The PenTest Index analysis, October 2026)
How many devices in hospitals carry a known flaw?Companies that scan hospital networksClaroty, March 2025: 9% of the connected medical devices it analyzed carried a known exploited flaw
Which named flaws have evidence of real attacks in CISA's catalog?CISA's exploited list12 of the 536 (The PenTest Index analysis, October 2026)

Source: The PenTest Index analysis and the Claroty press release linked above, checked October 9, 2026 (UTC).

Units trip people up most. Claroty reported its riskiest mix (a known exploited flaw tied to ransomware, plus an insecure internet connection) in 1% of devices but 89% of organizations. Both are right. One hospital can own thousands of devices, and it takes only one to count the hospital.

The same report shows how much device type matters. It puts that riskiest mix at 8% of imaging systems and 0.5% of patient devices in its sample.

What do CVE, KEV and CVSS mean?

They do three different jobs. A CVE names a flaw, KEV says a flaw has been used in real attacks, and CVSS scores how bad a flaw could be.

Terms that get mixed up

What do CVE, KEV and CVSS mean?
TermPlain meaningWhat it does not tell you
CVEThe public ID for one disclosed flawHow many devices have it
KEVCISA's list of flaws with reliable evidence of real attacksThat your device was attacked
CVSS base scoreA 0 to 10 score for how severe the flaw isThe risk at your hospital, or to a patient
CWEA label for the kind of mistake behind the flawHow easy the flaw is to use
AdvisoryA notice about one or more flawsThat there is only one flaw, or any attack
PatchA software change meant to fix a flawThat every device in use got it

Source: definitions from CISA, FIRST and MITRE, put in plain words by The PenTest Index.

Does the FDA require penetration testing for medical devices?

The law does not name penetration testing, but the FDA's guidance recommends it. Section 524B applies to qualifying FDA applications or submissions for "cyber devices" filed on or after March 29, 2023. It requires a security plan, a patching process and a list of software parts. The FDA's guidance, dated February 3, 2026, lists five things a penetration test report should include.

A penetration test is when trusted experts try to break into a product the way a real attacker would, so the maker can fix what they find.

The law and the guidance, side by side

Does the FDA require penetration testing for medical devices?
The lawThe FDA's guidance
What it isSection 524B of the Federal Food, Drug, and Cosmetic Act"Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions"
DateIn force March 29, 2023Issued February 3, 2026. It replaces the June 27, 2025 version.
ForceRequired for qualifying premarket applications or submissions for "cyber devices," including device changes that need a new submissionRecommendations are nonbinding; laws cited in the guidance still apply. The FDA says "should" means "suggested or recommended, but not required."
What it asks forA plan to find and fix flaws after sale. Processes that keep the device secure, with updates and patches. A software bill of materials (SBOM), which is a list of the software parts inside.Security testing, including penetration testing, and the test report itself.

Source: FDA, Cybersecurity and the premarket cybersecurity guidance, checked October 9, 2026 (UTC). A "cyber device" has software and technology validated, installed or authorized by its sponsor, can connect to the internet, and could be open to cyber threats. The sponsor is the person or company making the FDA submission. Read the FDA's exact definition and submission rules. The guidance also covers devices with software, firmware or programmable logic that do not connect to a network.

The FDA says penetration test reports "should be provided and include the following elements":

  1. Independence and technical expertise of testers
  2. Scope of testing
  3. Duration of testing
  4. Testing methods employed
  5. Test results, findings, and observations

Three more lines from the same guidance tie back to the data on this page.

  • On exploited flaws: vulnerabilities in CISA's Known Exploited Vulnerabilities Catalog "should be designed out of the device, as they are already being exploited." All 12 in this dataset came in through outside software.
  • On passwords: makers should test for credentials that are "'hardcoded,' default, easily guessed, and easily compromised." Forty-two flaws here concern hard-coded or default passwords and keys.
  • On timing: after release, cybersecurity testing "should be performed at regular intervals commensurate with the risk (e.g., annually)." Annual testing is an example based on risk, not a rule requiring every device to have a yearly penetration test.

One thing may confuse a careful reader. On October 9, 2026 (UTC), the FDA's own cybersecurity page still showed the June 27, 2025 date for this guidance. The PDF's cover says February 3, 2026.

If your device also has a web app or API, you can compare web and API penetration testing offers by the prices and scope they publish.

What should you do with a medical device vulnerability notice?

Match the notice to your exact product and software version first, then follow the maker's current instructions. Of 192 advisories, 68 show a later revision date than their number, so the first version you read may not be the last word.

If you make a device

  • Check your software parts list against CISA's exploited list. All 12 known exploited flaws here came in through outside software.
  • Test how the product checks identities. More than one in four flaws here is an authentication flaw.
  • Plan for a penetration test report that covers the FDA's five items.

If you run devices in a hospital

  • Look up your devices in the table above, then open CISA's page for each.
  • Ask each maker for its software parts list and its patch plan.
  • Work with the team that owns clinical safety before you change a device that is in use.

If you use one of these devices yourself

  • This page is not medical advice.
  • Follow your device maker's patch instructions. Do not try unofficial fixes you find online. Ask your care team if you are unsure. The FDA's plain-language guide is a good place to start.

Say you are a small device maker with a connected glucose meter and an FDA filing next spring. You would want a tester who can show independence, a clear scope, how long the test ran, the methods, and the findings. Those are the FDA's five items.

Getting ready to buy a penetration test for a device? Find My PenTest Match is our free scope checklist. It helps you write down what needs testing before you contact anyone.

How did we build this?

We checked all 192 CISA medical advisory pages on October 9, 2026 (UTC), including each CVE, weakness label, score, vector and credit line. We matched each CVE to CISA's Known Exploited Vulnerabilities catalog (version 2026.10.08, 1,739 entries). The analysis cutoff is October 8, 2026. The core counts come from the two advisory and CVE files. FDA matches, the linked maker table and quoted figures have their own source files.

Where the data came from

  • CISA's ICS medical advisory pages: 191 in the medical section, plus one with a medical number that CISA files with its other advisories (ICSMA-18-137-02).
  • CISA's Known Exploited Vulnerabilities catalog.
  • MITRE's CWE list, version 4.20, for weakness names and groups.
  • FDA notices, recall records and guidance for the FDA sections; the original producer of each figure in the source-check table.
  • Johnson & Johnson's original Carto 3 PDF for the separate linked-table check.

The rules we used

  1. One CVE is one vulnerability, however many advisories list it.
  2. Scores and weakness labels are the ones printed on CISA's pages. Where a CVE has a score in one advisory and only a range in another, we use the score.
  3. Severity bands follow FIRST's CVSS v3.1 scale.
  4. "Authentication flaw" means CWE-287 and everything MITRE files under it. The CSV field is authentication_flaw; it includes certificate and device-identity checks, not just logins. "Hard-coded or default passwords and keys" means CWE-798, CWE-259, CWE-321, CWE-1392 and CWE-1394.
  5. Each advisory gets one maker, vendor or project label and one of ten device groups. Both are our own sorting. The infusion and dispensing group includes medication and supply cabinets.
  6. "Year" is the year in CISA's advisory number.
  7. We count CVEs in the vulnerability descriptions, not stray IDs in navigation or unrelated references. In the Contec advisory, the credit paragraph has a typo, CVE-2025-1024. The vulnerability section, update log and researcher's disclosure identify CVE-2025-1204. We count the correct ID once.
  8. We count each CVE once overall. For a CVE listed more than once, a single published score takes priority over a range-only row. For CVE-2017-0143, this uses Baxter's 8.1 score in every group where that CVE appears. The per-advisory table keeps each page's own scores. All other repeated CVEs have matching values.
  9. We count outside or anonymous reporting credit together. It is a count of the credit lines, not proof that each reporter is independent or that a penetration test found the flaw.
  10. Percentages use the denominator printed beside them. They are rounded separately, half up, to one decimal.
  11. For the FDA recall count, retrieve all records matching reason_for_recall:cybersecurity, then count distinct res_event_number values. The 60 returned product records form 17 events.
  12. For the Carto 3 check, take the explicit CVE IDs on PDF pages 8–13, remove duplicates, join them to the core CVE IDs, then match that union to the same KEV catalog. The 183 IDs include 21 already counted: 536 + 183 − 21 = 698; 20 / 698 = 2.9%.

How we checked ourselves

  • We independently recomputed the submitted data and rechecked all 192 source pages. The 551 CVE listings and 536 distinct IDs matched.
  • We compared the inventory with CISA's medical advisory index and official advisory data repository. We used CISA's web pages when the versions disagreed.
  • We worked out all 526 populated score-and-vector rows again. All matched. The other 25 listings have only ranges; one repeated CVE has a single score in another advisory, leaving 24 distinct CVEs without a single score.
  • Our yearly advisory counts for 2016 to 2024 match the ones MedCrypt published in 2025. MedCrypt counted these advisories before we did.

Where CISA's data files and its web pages disagree, we used the web pages. For example, the repository inventory lacks four advisories, and its ICSMA-21-187-01 file omits CVE-2021-39369, which the page prints. Some scores, vectors and weakness labels also differ. We do not mix in the repository's extra single scores for page rows that give only ranges.

What does this data show, and what does it not show?

It shows what CISA has published about medical device flaws. It does not show how many devices in use are at risk today.

  • It counts notices, not danger. A maker that reports its own flaws gets a longer list.
  • "Known exploited" is narrow. Here it means a match to CISA's catalog. The 12 matches do not tell us that the other 524 have never been used, or that these attacks took place on medical devices.
  • It does not track fixes. A flaw named in 2018 may be long patched, or not.
  • Scores rate software, not patient harm.
  • Groups and maker names are ours. Sort the file differently and the device and maker tables will shift a little. The totals will not.
  • It cannot explain trends. We can see imaging software rise. We cannot see why.
  • It is U.S. government data. Flaws reported only to other countries' agencies, or never reported, are not here. CISA's medical category includes hospital software and shared components; it is not a list of FDA-cleared devices or a U.S. device sample.

You can read how The PenTest Index works and how we make money.

How do I cite this page?

Credit The PenTest Index for the counts and the matching, and keep CISA named as the source of the advisories. Keep the date with the number: 536 directly named CVEs and 12 catalog matches use the October 8, 2026 cutoff. Sources were checked October 9, 2026 (UTC).

Copy this citation:

The PenTest Index. "Medical Device Vulnerabilities: 536 CVEs, 12 on CISA's Exploited List." Data as of October 8, 2026; verified October 9, 2026 (UTC). https://thepentestindex.com/research/medical-device-vulnerabilities/

Or copy the finding in one sentence:

CISA's medical advisory pages directly name 536 distinct medical device vulnerabilities in 192 notices since 2016; 12 (2.2%) are on CISA's exploited list, all Microsoft or Apache flaws, according to The PenTest Index's October 2026 analysis of CISA data.

Can I reuse the tables, charts and data?

Yes. You may reuse our original counts, charts and device-group sorting; credit The PenTest Index by name. Keep CISA named as the source of its advisories and catalog; CISA releases the catalog under CC0. MITRE's CWE material and any manufacturer or vendor text keep their own attribution and terms. This permission covers our contribution, not rights in underlying source material.

Where can I download the data?

Every row behind this page is free to download as CSV, and each row carries its source link and check date.

The 13 CISA advisory CVE listings matching the Known Exploited Vulnerabilities catalog
Advisory IDCVE IDCWE IDCWE nameWeakness groupCVSS v3 scoreSeverityCVSS v3 vectorScore noteAuthentication flawHard-coded or default credentialMITRE mapping usageOn CISA KEVKEV vendorKEV nameKEV date addedKnown ransomware useSource URLCheck date
ICSMA-17-215-01CVE-2008-4250CWE-94Improper Control of Generation of Code ('Code Injection')Injection9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HnonoAllowed-with-ReviewyesMicrosoftMicrosoft Windows Buffer Overflow Vulnerability2026-05-20UnknownCISA advisory2026-10-09
ICSMA-17-215-01CVE-2017-7269CWE-119Improper Restriction of Operations within the Bounds of a Memory BufferMemory Safety9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HnonoDiscouragedyesMicrosoftMicrosoft Windows Server Buffer Overflow Vulnerability2021-11-03UnknownCISA advisory2026-10-09
ICSMA-17-215-02CVE-2015-1635CWE-94Improper Control of Generation of Code ('Code Injection')Injection9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HnonoAllowed-with-ReviewyesMicrosoftMicrosoft HTTP.sys Remote Code Execution Vulnerability2022-02-10UnknownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0143CWE-20Improper Input ValidationImproper Input ValidationScore range only on CISA page; no single scorenonoDiscouragedyesMicrosoftMicrosoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability2021-11-03KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0144CWE-20Improper Input ValidationImproper Input ValidationScore range only on CISA page; no single scorenonoDiscouragedyesMicrosoftMicrosoft SMBv1 Remote Code Execution Vulnerability2022-02-10KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0145CWE-20Improper Input ValidationImproper Input ValidationScore range only on CISA page; no single scorenonoDiscouragedyesMicrosoftMicrosoft SMBv1 Remote Code Execution Vulnerability2022-02-10KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0146CWE-20Improper Input ValidationImproper Input ValidationScore range only on CISA page; no single scorenonoDiscouragedyesMicrosoftMicrosoft Windows SMB Remote Code Execution Vulnerability2022-03-25KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0148CWE-20Improper Input ValidationImproper Input ValidationScore range only on CISA page; no single scorenonoDiscouragedyesMicrosoftMicrosoft SMBv1 Server Remote Code Execution Vulnerability2022-04-06KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0147CWE-200Exposure of Sensitive Information to an Unauthorized ActorSensitive Information Exposure5.9MediumAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NnonoDiscouragedyesMicrosoftMicrosoft Windows SMBv1 Information Disclosure Vulnerability2022-05-24KnownCISA advisory2026-10-09
ICSMA-18-058-02CVE-2017-0199CWE-264Permissions, Privileges, and Access ControlsCategory ID only (no group)Score range only on CISA page; no single scorenonoProhibitedyesMicrosoftMicrosoft Office and WordPad Remote Code Execution Vulnerability2021-11-03KnownCISA advisory2026-10-09
ICSMA-20-049-01CVE-2019-0708CWE-20Improper Input ValidationImproper Input Validation9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HnonoDiscouragedyesMicrosoftMicrosoft Remote Desktop Services Remote Code Execution Vulnerability2021-11-03KnownCISA advisory2026-10-09
ICSMA-20-170-01CVE-2017-0143CWE-20Improper Input ValidationImproper Input Validation8.1HighAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HnonoDiscouragedyesMicrosoftMicrosoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability2021-11-03KnownCISA advisory2026-10-09
ICSMA-21-187-01CVE-2020-1938CWE-20Improper Input ValidationImproper Input Validation9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HnonoDiscouragedyesApacheApache Tomcat Improper Privilege Management Vulnerability2022-03-03UnknownCISA advisory2026-10-09

Source: The CISA advisory source URL and check date appear in each row; KEV fields use the catalog version stated in the data.

Questions people ask

What is a medical device vulnerability?

A medical device vulnerability is a security flaw in a medical device or its software. Someone could use it to break in, steal data, or change how the device works. CISA has named 536 of them in 192 advisories since 2016.

How many medical device vulnerabilities are there?

CISA's medical advisory pages directly name 536 in 192 advisories, from March 29, 2016 to October 8, 2026. Two early advisories also report 1,418 and 460 flaws in outside software without naming each one. Their sum is 1,878, but unknown overlap means we cannot add it to the 536 distinct CVEs.

What is the most common medical device vulnerability?

Access control. Of the 536 vulnerabilities, 210 (39.2%) are access control flaws and 152 (28.4%) are authentication flaws: weak checks of a claimed identity. Forty-two are hard-coded or default passwords and keys.

Does a known vulnerability mean a medical device was hacked?

No. A vulnerability is a flaw that could be used in an attack. Only 12 of the 536 are on CISA's list of flaws used in real attacks, and even that list does not say which devices were hit.

Which medical devices have the most security advisories?

Imaging software has the most: 43 of 192 advisories (22.4%). Infusion pumps, medication and supply systems have 26, and patient monitors have 25. More advisories does not mean more danger.

Is there a medical device vulnerability database?

CISA posts each medical advisory on its website, and the FDA lists 18 cybersecurity safety notices. This page puts all 192 CISA advisories in one free file, with each flaw's score, weakness type and known-exploited status.

What percentage of medical devices are vulnerable?

These sources do not give one current rate for all medical devices. Claroty reported in March 2025 that 9% of the connected medical devices it analyzed carried a known exploited flaw. Always keep the company, the year and the unit with the number.

Where does "6.2 vulnerabilities per medical device" come from?

The earliest source we found is a February 7, 2018 blog post by a security vendor, Sensato. It gives no sample, dates or method. The FBI repeated the figure in 2022, and the GAO repeated the FBI in 2023.

Should a patient stop using a device named in an advisory?

A table cannot decide that. Talk with your care team and follow the maker's current instructions. The FDA says that for the 18 cases it lists, it is not aware of any patient injuries or deaths tied to cybersecurity incidents.

Sources

Sources were checked on October 9, 2026 (UTC). The analysis cutoff is October 8, 2026; the KEV catalog version is 2026.10.08. Historical figures keep the dates of their original reports.

  1. CISA, ICS advisories and ICS medical advisories (192 advisory pages). https://www.cisa.gov/news-events/ics-advisories
  2. CISA, Known Exploited Vulnerabilities catalog, version 2026.10.08. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. CISA, how vulnerabilities are added to the catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities
  4. CISA, advisory data files (cross-check). https://github.com/cisagov/CSAF
  5. CISA, catalog data and CC0 license. https://github.com/cisagov/kev-data
  6. Johnson & Johnson, Carto 3 operating-system patch advisory, April 2018. https://www.productsecurity.jnj.com/sites/default/files/2023-10/CARTO3v4-Advisory-040918.pdf
  7. MITRE, CWE view 1400. https://cwe.mitre.org/data/definitions/1400.html
  8. FIRST, CVSS v3.1 specification and user guide. https://www.first.org/cvss/v3.1/specification-document
  9. FDA, Cybersecurity (safety communications table). https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
  10. FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, February 3, 2026. https://www.fda.gov/media/119933/download
  11. FDA, Contec and Epsimed patient monitors safety communication, updated July 2, 2025. https://www.fda.gov/medical-devices/safety-communications/cybersecurity-vulnerabilities-certain-patient-monitors-contec-and-epsimed-fda-safety-communication
  12. FDA, Illumina Universal Copy Service letter, April 27, 2023. https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks
  13. FDA, device recall data (openFDA), data updated October 8, 2026. https://api.fda.gov/device/recall.json?search=reason_for_recall:cybersecurity&limit=100
  14. FDA, Medical Device Cybersecurity: What You Need to Know. https://www.fda.gov/consumers/consumer-updates/medical-device-cybersecurity-what-you-need-know
  15. GAO, GAO-24-106683, December 21, 2023. https://www.gao.gov/assets/gao-24-106683.pdf
  16. FBI, Private Industry Notification 20220912-001, September 12, 2022. https://www.ic3.gov/CSA/2022/220912.pdf
  17. Sensato, blog post, February 7, 2018. https://www.sensato.co/post/endless-terrifying-possibilities-call-for-a-good-medical-device-cop
  18. MedTech Dive, December 1, 2021. https://www.medtechdive.com/news/cybersecurity-medical-devices-hospital-divide-fda/609252/
  19. Cynerio, press release, January 19, 2022 (archived copy). https://web.archive.org/web/20220527214113/https://www.cynerio.com/blog/cynerio-research-finds-critical-medical-device-risks-continue-to-threaten-hospital-security-and-patient-safety
  20. Unit 42, Palo Alto Networks, March 2, 2022. https://unit42.paloaltonetworks.com/infusion-pump-vulnerabilities/
  21. Claroty, press release, March 26, 2025. https://claroty.com/press-releases/new-research-from-clarotys-team82-highlights-riskiest-medical-device-exposures-in-healthcare-environments
  22. Claroty, State of CPS Security: Healthcare Exposures 2025. https://web-assets.claroty.com/resource-downloads/state-of-cps-security-healthcare-2025.pdf
  23. Health-ISAC, Finite State and Securin, 2023 State of Cybersecurity for Medical Devices and Healthcare Systems. https://health-isac.org/wp-content/uploads/11883-StateMedSecurityReport_v6.pdf
  24. MedCrypt, ICS-CERT medical device advisory trends, April 2, 2025. https://www.medcrypt.com/cybersecurity-whitepapers/whitepapers-ics-cert-2024-medical-device-cybersecurity-trends
  25. Menon, Frontiers in Digital Health, March 2026. https://www.frontiersin.org/journals/digital-health/articles/10.3389/fdgth.2026.1701551/full
  26. FDA, Cybersecurity in Medical Devices Frequently Asked Questions. https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs
  27. Baxter, acquisition of Hillrom completed December 13, 2021; company release filed with the SEC. https://www.sec.gov/Archives/edgar/data/10456/000162828021024946/bax-20211213pressreleasexe.htm
  28. FDA, URGENT/11 press release, October 1, 2019. https://www.fda.gov/news-events/press-announcements/fda-informs-patients-providers-and-manufacturers-about-potential-cybersecurity-vulnerabilities
  29. MITRE, CWE version 4.20 data. https://cwe.mitre.org/data/xml/cwec_v4.20.xml.zip

The PenTest Index Research is the research and reference section of thepentestindex.com.