HOMEVULNERABILITIESCVE-2022-32537
MEDIUM

CVE-2022-32537

CWE-693Published: December 12, 2022· Updated: Jun 17, 2026

4.8
CVSS v3.1

Official Description

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

NVD Source

Technical Analysis

CVE-2022-32537 requires adjacent network access, limiting remote exploitation but still posing risk in shared or local network environments.

Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

A successful exploit results in full integrity compromise (data manipulation), with a CVSS base score of 4.8.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorAdjacent
Attack ComplexityHigh
Privileges Req.Low
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityNone
IntegrityHigh
AvailabilityNone
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Vendors & Products

medtronic56 product(s)
guardian link 2 transmitter mmt-7730 firmwareguardian link 2 transmitter mmt-7730guardian link 2 transmitter mmt-7731 firmwareguardian link 2 transmitter mmt-7731guardian link 2 transmitter mmt-7738 firmwareguardian link 2 transmitter mmt-7738guardian link 2 transmitter mmt-7775 firmwareguardian link 2 transmitter mmt-7775guardian link 3 transmitter mmt-7810 firmwareguardian link 3 transmitter mmt-7810guardian link 3 transmitter mmt-7811 firmwareguardian link 3 transmitter mmt-7811+44
Source: NVD CPE · 56 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (4)

Quick Facts

CVE IDCVE-2022-32537
CVSS Score4.8 / 10
SeverityMEDIUM
WeaknessCWE-693
CISA KEVNo
Affected1 vendor(s)
PublishedDec 12, 2022

Related CVEs (CWE-693)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2022-32537 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.