CVE-2017-12716
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers store the optional patient information without encryption. CVSS v3 base score: 3.1, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before f0b.0e.7e |
| Running on/with | Platform Versions |
|---|---|
Abbott Accent | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before f0b.0e.7e |
| Running on/with | Platform Versions |
|---|---|
Abbott Anthem | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before f10.08.6c |
| Running on/with | Platform Versions |
|---|---|
Abbott Accent Mri | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before f10.08.6c |
| Running on/with | Platform Versions |
|---|---|
Abbott Accent St | All versions |
Related CWEs
CWE-311
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.