CVE-2017-12716 Information

Description

Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally the Accent and Anthem pacemakers store the optional patient information without encryption. CVSS v3 base score: 3.1 CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

CVSS Vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

http://www.securityfocus.com/bid/100523 https://ics-cert.us-cert.gov/advisories/ICSMA-17-241-01

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: