CVE-2023-25931

Medtronic Micro Clinician & InterStim X Clinician App Password Reset Issue

Description

Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy application, which has greater control over therapy parameters than the patient app. Changes still cannot be made outside of the established therapy parameters of the programmer. For unauthorized access to occur, an individual would need physical access to the Smart Programmer.

Remediation

Solution:

  • Current versions of the application has mitigated this vulnerability. Please refer to the Medtronic Security Bulletin for update guidance. 

Categories

6.4
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.11%
Vendor Advisory medtronic.com
Affected: Medtronic InsterStim Applications
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-25931?
CVE-2023-25931 has been scored as a medium severity vulnerability.
How to fix CVE-2023-25931?
To fix CVE-2023-25931: Current versions of the application has mitigated this vulnerability. Please refer to the Medtronic Security Bulletin for update guidance. 
Is CVE-2023-25931 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-25931 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-25931?
CVE-2023-25931 affects Medtronic InsterStim Applications.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.