A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24844 | A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world. |
Fixes
Solution
No solution given by the vendor.
Workaround
Boston Scientific is in the process of transitioning all users to a replacement programmer with enhanced security, the LATITUDE Programming System, Model 3300. Boston Scientific will not issue a product update to address the identified vulnerabilities in the ZOOM LATITUDE Programming System, Model 3120.
References
| Link | Providers |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsma-21-273-01 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-17T03:33:08.540Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38392
No data.
Status : Modified
Published: 2021-10-04T18:15:09.110
Modified: 2024-11-21T06:16:59.043
Link: CVE-2021-38392
No data.
OpenCVE Enrichment
No data.
EUVD