CVE-2023-31222

CRITICAL

Medtronic's Paceart Optima <1.11 - Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.2580
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
medtronic/paceart_optima < 1.12
Published Jun 29, 2023
Tracked Since Feb 18, 2026