Medtronic Paceart MSMQ Deserialization of Untrusted Data
Vulnerability Description
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-31222
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Medtronic
References
More from Medtronic
View All →Affected Vendor
Medtronic
View all reports →