CVE-2017-12712 Vulnerability Details

  /     /     /  

CVE-2017-12712 Metadata Quick Info

CVE Published: 25/04/2018 | CVE Updated: 17/09/2024 | CVE Year: 2017
Source: icscert | Vendor: Abbott Laboratories | Product: Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI.
Status : PUBLISHED

CVE-2017-12712 Description

The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-287
CWE Name: Improper authentication CWE-287
Source: Abbott Laboratories

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).