CVE-2021-38398
Summary
| CVE | CVE-2021-38398 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-04 18:15:00 UTC |
| Updated | 2022-09-10 02:44:00 UTC |
| Description | The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities. |
Risk And Classification
Problem Types: CWE-1329
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bostonscientific | Zoom Latitude Pogrammer/recorder/monitor 3120 | - | All | All | All |
| Operating System | Bostonscientific | Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | All | All | All | All |
| Hardware | Bostonscientific | Zoom Latitude Programming System Model 3120 | - | All | All | All |
| Operating System | Bostonscientific | Zoom Latitude Programming System Model 3120 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Boston Scientific Zoom Latitude | CISA | MISC | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Endres Puschner - Max Planck Institute for Security and Privacy, Bochum, Christoph Saatjohann - FH Münster University of Applied Sciences, Christian Dresen - FH Münster University of Applied Sciences, and Markus Willing - University of Muenster, discovered these issues as part of broader academic research of cardiac devices and reported them to Boston Scientific.
There are currently no legacy QID mappings associated with this CVE.