Medtronic CareLink 2090 Programmer Recalled for Software Vulnerability
Medtronic is recalling CareLink 2090 Programmers worldwide due to a vulnerability that allows unauthorized software updates during the SDN download process.
What this means for you
Real risk of harm even if no illness or injury has been reported yet. Stop using the product and follow the agency's guidance.
Our severity reasoning: The recall is classified as FDA Class II and involves a security vulnerability in a medical device that poses a risk of harm, but no specific injuries or illnesses have been reported in the source text.
Plain-English summary
Medtronic Inc. is recalling the Medtronic CareLink 2090 Programmer. The recall involves 30,172 units distributed worldwide, covering all serial numbers. The recall is classified as Class II by the U.S. Food and Drug Administration.
The recall is being issued because vulnerabilities were identified in the SDN download process. These vulnerabilities may allow an individual with malicious intent to update the programmers with non-Medtronic software during an SDN download.
Healthcare providers and patients using the Medtronic CareLink 2090 Programmer should contact Medtronic for instructions on how to address the software vulnerability.
The recalled product
- Product
- Medtronic CareLink 2090 Programmer
- Affected units
- 30,172
Is your product affected?
Check your packaging against the codes below. If any of them match, the product is part of this recall.
Lot numbers (1)
- All Serial Numbers
Distribution
Distribution scope not specified by the agency.
Part of a larger recall action
This product is one of 2 recalled by Medtronic Inc., Cardiac Rhythm and Heart Failure (CRHF) under a single FDA (Devices) recall action. The agency files each product separately, so the size of the action is not visible from this page alone.
See all 2 products in this recall →Related recalls
Same manufacturer · Medtronic Inc., Cardiac Rhythm and Heart Failure (CRHF)
See all →- CriticalMedtronic CRT-D Defibrillators: Rare Energy Output Failure Risk During Therapy
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Cardioverter Defibrillators Recalled for Reduced Therapy Output
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Defibrillators Recalled for Potential Therapy Delivery Failure
FDA (Devices) · 2023-06-28
- SevereImplantable Cardioverter Defibrillators at Risk of Reduced Energy Output
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Cardioverter Defibrillator may lose energy output during therapy
FDA (Devices) · 2023-06-28
Same hazard · software vulnerability
See all →- ModerateRevolution CT ES X-ray Computed Tomography System Security Vulnerability Recall
FDA (Devices) · 2026-05-20
- HighPyxis Medication and Anesthesia Dispensing Systems Recalled for Software Vulnerabilities
FDA (Devices) · 2025-02-19
- High
- HighTorrent Suite Dx Software versions affected by cybersecurity vulnerability
FDA (Devices) · 2024-04-10
- ModerateSiemens Lantis 6.1 Commander Recalled for Windows RDP Vulnerability
FDA (Devices) · 2019-08-14