CVE-2013-7395 describes a critical vulnerability in ZOLL Defibrillator/Monitor X Series devices, where hardcoded default supervisor and service passwords allow unauthorized access. A physically proximate attacker could exploit this to modify device configurations, potentially leading to a denial of service with severe adverse human health effects. While the CVSS score is 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), indicating local access and low attack complexity, the impact on patient safety is high. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
xCPE matchmatch criteria | cpe:2.3:h:zoll:monitor\/defibrillator:x:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.