CVE-2022-32537

MEDIUM

Medtronic - Info Disclosure

Title source: llm

Description

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

Scores

CVSS v3 4.8
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-693
Status published

Affected Products (28)

medtronic/guardian_link_2_transmitter_mmt-7730_firmware
medtronic/guardian_link_2_transmitter_mmt-7731_firmware
medtronic/guardian_link_2_transmitter_mmt-7738_firmware
medtronic/guardian_link_2_transmitter_mmt-7775_firmware
medtronic/guardian_link_3_transmitter_mmt-7810_firmware
medtronic/guardian_link_3_transmitter_mmt-7811_firmware
medtronic/minimed_620g_mmt-1750_firmware
medtronic/minimed_630g_mmt-1715_firmware
medtronic/minimed_630g_mmt-1754_firmware
medtronic/minimed_630g_mmt-1755_firmware
medtronic/minimed_640g_mmt-1711_firmware
medtronic/minimed_640g_mmt-1712_firmware
medtronic/minimed_640g_mmt-1751_firmware
medtronic/minimed_640g_mmt-1752_firmware
medtronic/minimed_670g_mmt-1740_firmware
... and 13 more

Timeline

Published Dec 12, 2022
Tracked Since Feb 18, 2026