2024-07-14 02:06:08 +00:00

860 lines
24 KiB
JSON

{
"id": "CVE-2022-32537",
"sourceIdentifier": "security@medtronic.com",
"published": "2022-12-12T13:15:12.263",
"lastModified": "2023-11-07T03:47:51.340",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance\n"
},
{
"lang": "es",
"value": "Existe una vulnerabilidad que podr\u00eda permitir que un usuario no autorizado conozca aspectos del protocolo de comunicaci\u00f3n utilizado para emparejar componentes del sistema mientras la bomba se empareja con otros componentes del sistema. La explotaci\u00f3n requiere proximidad de se\u00f1al inal\u00e1mbrica cercana con el paciente y el dispositivo; Se requieren conocimientos t\u00e9cnicos avanzados para su explotaci\u00f3n. Consulte el Bolet\u00edn de seguridad de productos de Medtronic para obtener orientaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 4.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.6
},
{
"source": "security@medtronic.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 4.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
},
{
"source": "security@medtronic.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-693"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_2_transmitter_mmt-7730_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1C5AA07C-EB49-4DB1-91C5-5B7FF9BC60DE"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_2_transmitter_mmt-7730:-:*:*:*:*:*:*:*",
"matchCriteriaId": "615FEF55-7051-4CE2-9D10-2D8643C8E599"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_2_transmitter_mmt-7731_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B1E499AF-6392-4D48-A2AA-6DF89B725CF5"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_2_transmitter_mmt-7731:-:*:*:*:*:*:*:*",
"matchCriteriaId": "60CD7CC1-83A0-4890-9C3D-80CFC435469A"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_2_transmitter_mmt-7738_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5D61D148-8A08-402B-8252-A0C7E2C1606D"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_2_transmitter_mmt-7738:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6A183442-FB5F-4BD0-A390-05E1D2BB9B9B"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_2_transmitter_mmt-7775_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "53B3B95A-1706-45A3-A70E-1B598F7E6E24"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_2_transmitter_mmt-7775:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8CB928B7-ABD2-40A7-9CBE-DA77A2FB3FC6"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_3_transmitter_mmt-7810_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "795ADE03-3C93-48DB-B0C0-9D732A56619A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_3_transmitter_mmt-7810:-:*:*:*:*:*:*:*",
"matchCriteriaId": "209B1C70-6ABE-4AAE-B413-36BCED848C1E"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:guardian_link_3_transmitter_mmt-7811_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "827E4A1F-E3A7-4BC1-8671-2E29A9690885"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:guardian_link_3_transmitter_mmt-7811:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A710ACB1-FB33-4410-ACB5-628BEF78B2DF"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_620g_mmt-1750_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "52100FBF-B15B-4C23-AF3E-D5B08A20138C"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_620g_mmt-1750:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1C6E5125-613D-4318-8894-A0EA7E70A23A"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_630g_mmt-1715_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D7A62CB9-0CB5-4E69-865B-6DCCC5E52623"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_630g_mmt-1715:-:*:*:*:*:*:*:*",
"matchCriteriaId": "71B6DDBD-7710-48F0-AE17-666B0ABD85C7"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_630g_mmt-1754_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BD1DAC2D-E81E-4A9F-8EC3-475B68D08E4D"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_630g_mmt-1754:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3AD50208-75AD-4201-B50B-9B3C2B92D4B3"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_630g_mmt-1755_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1E7195EE-CFDC-4592-A40C-E4C809B3A299"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_630g_mmt-1755:-:*:*:*:*:*:*:*",
"matchCriteriaId": "EFB1067F-85DD-4AC3-9A2D-96AF7487A169"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_640g_mmt-1711_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1DE3A51F-C0B9-4FE8-937F-3D0A65447B86"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_640g_mmt-1711:-:*:*:*:*:*:*:*",
"matchCriteriaId": "79D08E98-E921-48B6-860F-941AEAE6A1C6"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_640g_mmt-1712_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D58A6AA9-E899-4EB0-B43A-5B55142037C9"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_640g_mmt-1712:-:*:*:*:*:*:*:*",
"matchCriteriaId": "45D90195-01D6-40BC-B4CF-36FA555D1EC2"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_640g_mmt-1751_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FB9F223A-63E6-4A62-B7D1-BA58547E8611"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_640g_mmt-1751:-:*:*:*:*:*:*:*",
"matchCriteriaId": "256F9F01-2109-4857-ABE5-3EA1284F8D93"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_640g_mmt-1752_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "DF1C533C-43A1-407D-88DF-C9467D2B63E8"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_640g_mmt-1752:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6685F923-556D-4274-99B4-6DB7A2FC75B8"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1740_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "22187A09-60DA-4359-B310-F9C982795EEF"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1740:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E0000AE0-FD3F-4CC8-B00D-A1C58EE1BB1B"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1741_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0F8B6AAF-5043-48B7-A638-98F3624202ED"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1741:-:*:*:*:*:*:*:*",
"matchCriteriaId": "12584AA5-E57C-473A-8E1F-4398ADADFCD7"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1742_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B5AEA1F9-2259-44F7-B175-0C26ECDF228A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1742:-:*:*:*:*:*:*:*",
"matchCriteriaId": "49C86FAB-7C0D-4F81-9CA2-2AF809760029"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1760_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FF1A796D-25D0-4640-BF69-DE2886608F9B"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1760:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F110C3E4-808E-4DF0-9952-E3C38EA36D66"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1761_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A4235875-59AE-42FB-B66C-03EDE76B12F0"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1761:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A78FB8FF-C0C1-4678-B686-295ED7040659"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1762_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E7BC3BEE-987F-4B65-9FE3-604FCB2487BC"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1762:-:*:*:*:*:*:*:*",
"matchCriteriaId": "81B931BE-24E0-4D5F-866D-E715E4673474"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1780_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "665944D0-B221-4BC3-BE1B-0A6F77B4BCF1"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1780:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9123F954-4788-417D-B06C-3EA8F9C08165"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1781_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "52C27006-E33E-4025-B20A-60A2D9DB451B"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1781:-:*:*:*:*:*:*:*",
"matchCriteriaId": "48985412-63A5-4296-9EBD-7FBE617E5FC1"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:minimed_670g_mmt-1782_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A0BB979C-5A06-4975-83B7-D92A29E1FC03"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:minimed_670g_mmt-1782:-:*:*:*:*:*:*:*",
"matchCriteriaId": "EEE3ED1A-6C7D-4D7F-A650-E905C8E92C2C"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mmt-1151_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9700FDA5-541C-48FF-A0FE-5B14B6B8A60A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mmt-1151:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3056ECAE-8567-4704-ABEB-F07E2E16D50A"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mmt-1152_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5B8B0E02-BA08-4EBF-9D71-AD1B35252E5F"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mmt-1152:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5037978F-0204-4304-83BC-4201CCDCEB5C"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mmt-1351_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CB0E24E7-9E50-4BA3-9F8A-4B44F84BF765"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mmt-1351:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E08AC3AC-ED38-43FA-932E-93821076040D"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mmt-1352_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B54B7156-1903-4274-9743-9D69DF1D52D6"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mmt-1352:-:*:*:*:*:*:*:*",
"matchCriteriaId": "08D75197-E41F-47BD-8079-38DB5659CF21"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:medtronic:mmt-7306_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0967A9CC-66FF-4C20-80BA-BEA5945EB793"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:medtronic:mmt-7306:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7F3D5290-AC9A-4687-B634-CFF21FEB84FE"
}
]
}
]
}
],
"references": [
{
"url": "https://global.medtronic.com/xg-en/product-security/security-bulletins/minimed-600-series-communication-issue.html",
"source": "security@medtronic.com",
"tags": [
"Mitigation",
"Vendor Advisory"
]
},
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsma-22-263-01",
"source": "security@medtronic.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
}
]
}