ID

VAR-201408-0001


CVE

CVE-2007-6756


TITLE

ZOLL Vulnerability to change device settings in multiple series of defibrillators

Trust: 0.8

sources: JVNDB: JVNDB-2007-006495

DESCRIPTION

ZOLL Defibrillator / Monitor M Series, E Series, and R Series have a default password for System Configuration mode, which allows physically proximate attackers to modify device configuration and cause a denial of service (adverse human health effects). ZOLL Defibrillator/Monitor M Series, E Series and R Series are all M, E, R series defibrillator devices used by ZOLL in the United States for emergency medical services. There are security vulnerabilities in various ZOLL Defibrillator/Monitor products. Because the System Configuration mode uses the default password. An attacker could exploit this vulnerability to modify the device configuration and cause a denial of service. Monitor/defibrillator is prone to a denial-of-service vulnerability

Trust: 2.43

sources: NVD: CVE-2007-6756 // JVNDB: JVNDB-2007-006495 // CNVD: CNVD-2014-05044 // BID: 81495

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-05044

AFFECTED PRODUCTS

vendor:zollmodel:monitor\/defibrillatorscope:eqversion:r

Trust: 1.6

vendor:zollmodel:monitor\/defibrillatorscope:eqversion:m

Trust: 1.6

vendor:zollmodel:monitor\/defibrillatorscope:eqversion:e

Trust: 1.6

vendor:zol medicalmodel:zoll defibrillatorscope:eqversion:e series

Trust: 0.8

vendor:zol medicalmodel:zoll defibrillatorscope:eqversion:m series

Trust: 0.8

vendor:zol medicalmodel:zoll defibrillatorscope:eqversion:r series

Trust: 0.8

vendor:zollmodel:defibrillator monitor r seriesscope:eqversion:/

Trust: 0.6

vendor:zollmodel:defibrillator monitor e seriesscope:eqversion:/

Trust: 0.6

vendor:zollmodel:defibrillator monitor m seriesscope:eqversion:/

Trust: 0.6

vendor:zollmodel:monitor%2fdefibrillator rscope: - version: -

Trust: 0.3

vendor:zollmodel:monitor%2fdefibrillator mscope: - version: -

Trust: 0.3

vendor:zollmodel:monitor%2fdefibrillator escope: - version: -

Trust: 0.3

sources: CNVD: CNVD-2014-05044 // BID: 81495 // JVNDB: JVNDB-2007-006495 // CNNVD: CNNVD-201408-170 // NVD: CVE-2007-6756

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-6756
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-6756
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-05044
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201408-170
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2007-6756
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-05044
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-05044 // JVNDB: JVNDB-2007-006495 // CNNVD: CNNVD-201408-170 // NVD: CVE-2007-6756

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2007-006495 // NVD: CVE-2007-6756

THREAT TYPE

local

Trust: 0.9

sources: BID: 81495 // CNNVD: CNNVD-201408-170

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201408-170

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-006495

PATCH

title:M Series Configuration Guideurl:http://www.zoll.com/WorkArea/DownloadAsset.aspx?id=2386

Trust: 0.8

title:E Series Configuration Guideurl:http://www.zoll.com/WorkArea/DownloadAsset.aspx?id=10018

Trust: 0.8

title:R Series Configuration Guideurl:http://www.zoll.com/WorkArea/DownloadAsset.aspx?id=18473

Trust: 0.8

sources: JVNDB: JVNDB-2007-006495

EXTERNAL IDS

db:NVDid:CVE-2007-6756

Trust: 3.3

db:JVNDBid:JVNDB-2007-006495

Trust: 0.8

db:CNVDid:CNVD-2014-05044

Trust: 0.6

db:CNNVDid:CNNVD-201408-170

Trust: 0.6

db:BIDid:81495

Trust: 0.3

sources: CNVD: CNVD-2014-05044 // BID: 81495 // JVNDB: JVNDB-2007-006495 // CNNVD: CNNVD-201408-170 // NVD: CVE-2007-6756

REFERENCES

url:http://www.zoll.com/workarea/downloadasset.aspx?id=2386

Trust: 2.5

url:http://www.zoll.com/workarea/downloadasset.aspx?id=10018

Trust: 1.9

url:http://www.zoll.com/workarea/downloadasset.aspx?id=18473

Trust: 1.9

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-6756

Trust: 1.4

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/95718

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-6756

Trust: 0.8

sources: CNVD: CNVD-2014-05044 // BID: 81495 // JVNDB: JVNDB-2007-006495 // CNNVD: CNNVD-201408-170 // NVD: CVE-2007-6756

CREDITS

Unknown

Trust: 0.3

sources: BID: 81495

SOURCES

db:CNVDid:CNVD-2014-05044
db:BIDid:81495
db:JVNDBid:JVNDB-2007-006495
db:CNNVDid:CNNVD-201408-170
db:NVDid:CVE-2007-6756

LAST UPDATE DATE

2025-04-13T23:39:09.742000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-05044date:2014-08-15T00:00:00
db:BIDid:81495date:2014-08-12T00:00:00
db:JVNDBid:JVNDB-2007-006495date:2014-08-14T00:00:00
db:CNNVDid:CNNVD-201408-170date:2014-08-14T00:00:00
db:NVDid:CVE-2007-6756date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-05044date:2014-08-15T00:00:00
db:BIDid:81495date:2014-08-12T00:00:00
db:JVNDBid:JVNDB-2007-006495date:2014-08-14T00:00:00
db:CNNVDid:CNNVD-201408-170date:2014-08-14T00:00:00
db:NVDid:CVE-2007-6756date:2014-08-12T16:55:04.567