MEDIUM · 4.8

CVE-2022-32537

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components....

Vulnerability Description

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
MedtronicGuardian Link 2 Transmitter Mmt-7730 Firmware-
MedtronicGuardian Link 2 Transmitter Mmt-7730-
MedtronicGuardian Link 2 Transmitter Mmt-7731 Firmware-
MedtronicGuardian Link 2 Transmitter Mmt-7731-
MedtronicGuardian Link 2 Transmitter Mmt-7738 Firmware-
MedtronicGuardian Link 2 Transmitter Mmt-7738-
MedtronicGuardian Link 2 Transmitter Mmt-7775 Firmware-
MedtronicGuardian Link 2 Transmitter Mmt-7775-
MedtronicGuardian Link 3 Transmitter Mmt-7810 Firmware-
MedtronicGuardian Link 3 Transmitter Mmt-7810-
MedtronicGuardian Link 3 Transmitter Mmt-7811 Firmware-
MedtronicGuardian Link 3 Transmitter Mmt-7811-
MedtronicMinimed 620G Mmt-1750 Firmware-
MedtronicMinimed 620G Mmt-1750-
MedtronicMinimed 630G Mmt-1715 Firmware-
MedtronicMinimed 630G Mmt-1715-
MedtronicMinimed 630G Mmt-1754 Firmware-
MedtronicMinimed 630G Mmt-1754-
MedtronicMinimed 630G Mmt-1755 Firmware-
MedtronicMinimed 630G Mmt-1755-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-32537?

CVE-2022-32537 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components....

How severe is CVE-2022-32537?

CVE-2022-32537 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-32537?

Check the references section above for vendor advisories and patch information. Affected products include: Medtronic Guardian Link 2 Transmitter Mmt-7730 Firmware, Medtronic Guardian Link 2 Transmitter Mmt-7730, Medtronic Guardian Link 2 Transmitter Mmt-7731 Firmware, Medtronic Guardian Link 2 Transmitter Mmt-7731, Medtronic Guardian Link 2 Transmitter Mmt-7738 Firmware.