Medtronic Paceart MSMQ Deserialization of Untrusted Data
CVE-2023-31222

9.8CRITICAL

Key Information:

Vendor

Medtronic

Vendor
CVE Published:
29 June 2023

What is CVE-2023-31222?

The vulnerability affects Medtronic's Paceart Optima system, allowing unauthorized access through improper deserialization of untrusted data in the Microsoft Messaging Queuing Service. This can lead to unauthorized manipulation of the system, resulting in potential data deletion, theft, or alteration. Furthermore, it poses a risk of using the Paceart Optima system as a launchpad for deeper network infiltration, jeopardizing sensitive healthcare data and operations.

Affected Version(s)

Paceart Optima Windows Versions 1.11 and earlier

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Medtronic
.
CVE-2023-31222 : Medtronic Paceart MSMQ Deserialization of Untrusted Data