Medtronic MiniMed 600 Series Pump System Communication Issue
CVE-2022-32537

4.8MEDIUM

Key Information:

Vendor

Medtronic

Vendor
CVE Published:
12 December 2022

What is CVE-2022-32537?

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

Affected Version(s)

Minimed 600 Series Insulin Pump 620G, 630G, 640G, 670G

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.