An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-24846 An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.
Fixes

Solution

No solution given by the vendor.


Workaround

Boston Scientific is in the process of transitioning all users to a replacement programmer with enhanced security, the LATITUDE Programming System, Model 3300. Boston Scientific will not issue a product update to address the identified vulnerabilities in the ZOOM LATITUDE Programming System, Model 3120.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T18:59:19.736Z

Reserved: 2021-08-10T00:00:00

Link: CVE-2021-38394

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-04T18:15:09.167

Modified: 2024-11-21T06:16:59.353

Link: CVE-2021-38394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.