ID

VAR-201804-0520


CVE

CVE-2017-12714


TITLE

Abbott Laboratories pacemakers Access control vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-013349

DESCRIPTION

Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities. Abbott Laboratories pacemakers Contains an access control vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Accent, Anthem, Accent MRI, Assurity, Allure, and Assurity MRI are all implantable medical devices from Abbott Laboratories. Battery life. Multiple Abbott Pacemakers are prone to the following multiple security vulnerabilities: 1. An authentication-bypass vulnerability 2. An information-disclosure vulnerability 3. A Denial-of-Service vulnerability Successful exploits may allow an attacker to gain unauthorized access or bypass intended security restrictions, obtain sensitive information or cause denial-of-service conditions

Trust: 2.61

sources: NVD: CVE-2017-12714 // JVNDB: JVNDB-2017-013349 // CNVD: CNVD-2017-23900 // BID: 100523 // IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6 // CNVD: CNVD-2017-23900

AFFECTED PRODUCTS

vendor:abbottmodel:assurityscope:ltversion:f14.07.80

Trust: 1.0

vendor:abbottmodel:accentscope:ltversion:f0b.0e.7e

Trust: 1.0

vendor:abbottmodel:anthemscope:ltversion:f0b.0e.7e

Trust: 1.0

vendor:abbottmodel:accent stscope:ltversion:f10.08.6c

Trust: 1.0

vendor:abbottmodel:assurity mriscope:ltversion:f17.01.49

Trust: 1.0

vendor:abbottmodel:allurescope:ltversion:f14.07.80

Trust: 1.0

vendor:abbottmodel:accent mriscope:ltversion:f10.08.6c

Trust: 1.0

vendor:abbottmodel:accentscope: - version: -

Trust: 0.8

vendor:abbottmodel:accent mriscope: - version: -

Trust: 0.8

vendor:abbottmodel:accent stscope: - version: -

Trust: 0.8

vendor:abbottmodel:allurescope: - version: -

Trust: 0.8

vendor:abbottmodel:anthemscope: - version: -

Trust: 0.8

vendor:abbottmodel:assurityscope: - version: -

Trust: 0.8

vendor:abbottmodel:assurity mriscope: - version: -

Trust: 0.8

vendor:abbottmodel:laboratories accent <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:laboratories anthem <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:laboratories accent mri <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:laboratories assurity <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:laboratories allure <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:laboratories assurity mri <augustscope:eqversion:282017

Trust: 0.6

vendor:abbottmodel:assurity mriscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:assurityscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:anthemscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:allurescope:eqversion:0

Trust: 0.3

vendor:abbottmodel:accent stscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:accent mriscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:accentscope:eqversion:0

Trust: 0.3

vendor:abbottmodel:assurity mri f17.01.49scope:neversion: -

Trust: 0.3

vendor:abbottmodel:assurity f14.07.80scope:neversion: -

Trust: 0.3

vendor:abbottmodel:anthem f0b.0e.7escope:neversion: -

Trust: 0.3

vendor:abbottmodel:allure f14.07.80scope:neversion: -

Trust: 0.3

vendor:abbottmodel:accent st f10.08.6cscope:neversion: -

Trust: 0.3

vendor:abbottmodel:accent mri f10.08.6cscope:neversion: -

Trust: 0.3

vendor:abbottmodel:accent f0b.0e.7escope:neversion: -

Trust: 0.3

vendor:accentmodel: - scope:eqversion:*

Trust: 0.2

vendor:anthemmodel: - scope:eqversion:*

Trust: 0.2

vendor:accent mrimodel: - scope:eqversion:*

Trust: 0.2

vendor:accent stmodel: - scope:eqversion:*

Trust: 0.2

vendor:assuritymodel: - scope:eqversion:*

Trust: 0.2

vendor:alluremodel: - scope:eqversion:*

Trust: 0.2

vendor:assurity mrimodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6 // CNVD: CNVD-2017-23900 // BID: 100523 // JVNDB: JVNDB-2017-013349 // NVD: CVE-2017-12714

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12714
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-12714
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-23900
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201709-085
value: MEDIUM

Trust: 0.6

IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2017-12714
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-23900
severity: MEDIUM
baseScore: 4.6
vectorString: AV:A/AC:H/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.2
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6
severity: MEDIUM
baseScore: 4.6
vectorString: AV:A/AC:H/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.2
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2017-12714
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6 // CNVD: CNVD-2017-23900 // JVNDB: JVNDB-2017-013349 // CNNVD: CNNVD-201709-085 // NVD: CVE-2017-12714

PROBLEMTYPE DATA

problemtype:CWE-920

Trust: 1.0

problemtype:CWE-284

Trust: 0.8

sources: JVNDB: JVNDB-2017-013349 // NVD: CVE-2017-12714

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201709-085

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201709-085

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-013349

PATCH

title:Top Pageurl:http://www.abbott.com/

Trust: 0.8

title:Abbott Laboratories Patches for Multiple Pacemaker Product Access Limiting Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/101203

Trust: 0.6

title:Multiple Abbott Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74540

Trust: 0.6

sources: CNVD: CNVD-2017-23900 // JVNDB: JVNDB-2017-013349 // CNNVD: CNNVD-201709-085

EXTERNAL IDS

db:NVDid:CVE-2017-12714

Trust: 3.5

db:ICS CERTid:ICSMA-17-241-01

Trust: 3.3

db:BIDid:100523

Trust: 1.9

db:CNVDid:CNVD-2017-23900

Trust: 0.8

db:CNNVDid:CNNVD-201709-085

Trust: 0.8

db:ICS CERTid:ICSMA-18-107-01

Trust: 0.8

db:JVNDBid:JVNDB-2017-013349

Trust: 0.8

db:AUSCERTid:ESB-2017.2157

Trust: 0.3

db:IVDid:CB95B3A8-887C-44B0-B1F4-C00D35D478D6

Trust: 0.2

sources: IVD: cb95b3a8-887c-44b0-b1f4-c00d35d478d6 // CNVD: CNVD-2017-23900 // BID: 100523 // JVNDB: JVNDB-2017-013349 // CNNVD: CNNVD-201709-085 // NVD: CVE-2017-12714

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsma-17-241-01

Trust: 3.3

url:http://www.securityfocus.com/bid/100523

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12714

Trust: 0.8

url:https://ics-cert.us-cert.gov/advisories/icsma-18-107-01

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12714

Trust: 0.8

url:http://www.abbott.com/

Trust: 0.3

url:http://abbott.mediaroom.com/2017-08-29-abbott-issues-new-updates-for-implanted-cardiac-devices

Trust: 0.3

url:https://www.auscert.org.au/bulletins/51662

Trust: 0.3

url:https://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm573669.htm

Trust: 0.3

sources: CNVD: CNVD-2017-23900 // BID: 100523 // JVNDB: JVNDB-2017-013349 // CNNVD: CNNVD-201709-085 // NVD: CVE-2017-12714

CREDITS

MedSec Holdings Ltd

Trust: 0.9

sources: BID: 100523 // CNNVD: CNNVD-201709-085

SOURCES

db:IVDid:cb95b3a8-887c-44b0-b1f4-c00d35d478d6
db:CNVDid:CNVD-2017-23900
db:BIDid:100523
db:JVNDBid:JVNDB-2017-013349
db:CNNVDid:CNNVD-201709-085
db:NVDid:CVE-2017-12714

LAST UPDATE DATE

2024-11-23T22:17:36.258000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-23900date:2017-08-30T00:00:00
db:BIDid:100523date:2017-08-29T00:00:00
db:JVNDBid:JVNDB-2017-013349date:2018-07-04T00:00:00
db:CNNVDid:CNNVD-201709-085date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12714date:2024-11-21T03:10:04.977

SOURCES RELEASE DATE

db:IVDid:cb95b3a8-887c-44b0-b1f4-c00d35d478d6date:2017-08-30T00:00:00
db:CNVDid:CNVD-2017-23900date:2017-08-30T00:00:00
db:BIDid:100523date:2017-08-29T00:00:00
db:JVNDBid:JVNDB-2017-013349date:2018-06-22T00:00:00
db:CNNVDid:CNNVD-201709-085date:2017-08-29T00:00:00
db:NVDid:CVE-2017-12714date:2018-04-25T13:29:00.287