CVE-2022-32537
Last modified
CVE-2022-32537 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance
Metrics
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Medtronic | Guardian Link 2 Transmitter Mmt-7730 Firmware | All versions |
| Medtronic | Guardian Link 2 Transmitter Mmt-7731 Firmware | All versions |
| Medtronic | Guardian Link 2 Transmitter Mmt-7738 Firmware | All versions |
| Medtronic | Guardian Link 2 Transmitter Mmt-7775 Firmware | All versions |
| Medtronic | Guardian Link 3 Transmitter Mmt-7810 Firmware | All versions |
| Medtronic | Guardian Link 3 Transmitter Mmt-7811 Firmware | All versions |
| Medtronic | Minimed 620g Mmt-1750 Firmware | All versions |
| Medtronic | Minimed 630g Mmt-1715 Firmware | All versions |
| Medtronic | Minimed 630g Mmt-1754 Firmware | All versions |
| Medtronic | Minimed 630g Mmt-1755 Firmware | All versions |
| Medtronic | Minimed 640g Mmt-1711 Firmware | All versions |
| Medtronic | Minimed 640g Mmt-1712 Firmware | All versions |
| Medtronic | Minimed 640g Mmt-1751 Firmware | All versions |
| Medtronic | Minimed 640g Mmt-1752 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1740 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1741 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1742 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1760 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1761 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1762 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1780 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1781 Firmware | All versions |
| Medtronic | Minimed 670g Mmt-1782 Firmware | All versions |
| Medtronic | Mmt-1151 Firmware | All versions |
| Medtronic | Mmt-1152 Firmware | All versions |
| Medtronic | Mmt-1351 Firmware | All versions |
| Medtronic | Mmt-1352 Firmware | All versions |
| Medtronic | Mmt-7306 Firmware | All versions |
References
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-263-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32537?
How severe is CVE-2022-32537?
How do I fix CVE-2022-32537?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-32531The Apache Bookkeeper Java Client (before 4.14.6 and also 4.…5.9
- CVE-2022-32532Apache Shiro before 1.9.1, A RegexRequestMatcher can be misc…9.8
- CVE-2022-32533Apache Jetspeed-2 does not sufficiently filter untrusted use…9.8
- CVE-2022-32534The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32535The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32536The user access rights validation in the web server of the B…8.8
- CVE-2022-3254The WordPress Classifieds Plugin WordPress plugin before 4.3…9.8
- CVE-2022-32540Information Disclosure in Operator Client application in BVM…5.9
- CVE-2022-32543An integer overflow vulnerability exists in the way ESTsoft …7.8
- CVE-2022-32544Operation restriction bypass vulnerability in Project of Cyb…4.3
- CVE-2022-32545A vulnerability was found in ImageMagick, causing an outside…7.8
- CVE-2022-32546A vulnerability was found in ImageMagick, causing an outside…7.8
Are you affected by CVE-2022-32537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
