CVE-2022-32537
MEDIUMMedtronic - Info Disclosure
Title source: llmDescription
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance
Scores
CVSS v3
4.8
EPSS
0.0011
EPSS Percentile
29.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (28)
medtronic/guardian_link_2_transmitter_mmt-7730_firmware
medtronic/guardian_link_2_transmitter_mmt-7731_firmware
medtronic/guardian_link_2_transmitter_mmt-7738_firmware
medtronic/guardian_link_2_transmitter_mmt-7775_firmware
medtronic/guardian_link_3_transmitter_mmt-7810_firmware
medtronic/guardian_link_3_transmitter_mmt-7811_firmware
medtronic/minimed_620g_mmt-1750_firmware
medtronic/minimed_630g_mmt-1715_firmware
medtronic/minimed_630g_mmt-1754_firmware
medtronic/minimed_630g_mmt-1755_firmware
medtronic/minimed_640g_mmt-1711_firmware
medtronic/minimed_640g_mmt-1712_firmware
medtronic/minimed_640g_mmt-1751_firmware
medtronic/minimed_640g_mmt-1752_firmware
medtronic/minimed_670g_mmt-1740_firmware
... and 13 more
Timeline
Published
Dec 12, 2022
Tracked Since
Feb 18, 2026