CVE-2017-12714

UnknownEPSS 0.66%

Last modified

CVE-2017-12714 is a vulnerability of currently unknown severity. Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

Metrics

EPSS Probability
0.66%

46.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AbbottAccent Firmware< f0b.0e.7e
AbbottAnthem Firmware< f0b.0e.7e
AbbottAccent Mri Firmware< f10.08.6c
AbbottAccent St Firmware< f10.08.6c
AbbottAssurity Firmware< f14.07.80
AbbottAllure Firmware< f14.07.80
AbbottAssurity Mri Firmware< f17.01.49

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-12714?
Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.
How severe is CVE-2017-12714?
Severity scoring for CVE-2017-12714 is pending analysis. The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2017-12714?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-12714?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST