Medtronic Paceart MSMQ Deserialization of Untrusted Data
CVE-2023-31222
9.8CRITICAL
What is CVE-2023-31222?
The vulnerability affects Medtronic's Paceart Optima system, allowing unauthorized access through improper deserialization of untrusted data in the Microsoft Messaging Queuing Service. This can lead to unauthorized manipulation of the system, resulting in potential data deletion, theft, or alteration. Furthermore, it poses a risk of using the Paceart Optima system as a launchpad for deeper network infiltration, jeopardizing sensitive healthcare data and operations.
Affected Version(s)
Paceart Optima Windows Versions 1.11 and earlier
References
EPSS Score
28% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Medtronic
