The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Abbott
Subscribe
|
Accent
Subscribe
Accent Firmware
Subscribe
Accent Mri
Subscribe
Accent Mri Firmware
Subscribe
Accent St
Subscribe
Accent St Firmware
Subscribe
Allure
Subscribe
Allure Firmware
Subscribe
Anthem
Subscribe
Anthem Firmware
Subscribe
Assurity
Subscribe
Assurity Firmware
Subscribe
Assurity Mri
Subscribe
Assurity Mri Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-4251 | The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-17T03:48:37.996Z
Reserved: 2017-08-09T00:00:00
Link: CVE-2017-12712
No data.
Status : Modified
Published: 2018-04-25T13:29:00.227
Modified: 2024-11-21T03:10:04.707
Link: CVE-2017-12712
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD