CVE-2022-32537

CVSS v3 Score
4.8
Medium

Vulnerability Description

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

CVSS:4.8(Medium)

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in you...

CVSS:4.8(Medium)

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVSS:4.7(Medium)

A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to ins...

CVSS:4.7(Medium)

A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass th...

CVSS:4.7(Medium)

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS:4.7(Medium)

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability