An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical's web site, Merlin.net, are not verified. This may allow a man-in-the-middle attacker to access or influence communications between the identified endpoints.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-14258 An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical's web site, Merlin.net, are not verified. This may allow a man-in-the-middle attacker to access or influence communications between the identified endpoints.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T14:55:34.850Z

Reserved: 2017-01-03T00:00:00

Link: CVE-2017-5149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-02-13T22:59:00.303

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-5149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses