CVE-2017-12712 affects Abbott Laboratories pacemakers manufactured before August 28, 2017, where a flaw in the authentication algorithm allows a nearby attacker to issue unauthorized commands via RF. This vulnerability carries a high CVSS v3 score of 8.8, indicating a severe risk due to an adjacent attack vector with low complexity, leading to high impact on confidentiality, integrity, and availability. While Abbott has released a firmware update, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not on the CISA KEV catalog, suggesting no active exploitation. However, it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< f0b.0e.7eCPE matchmatch criteria | cpe:2.3:o:abbott:accent_firmware:*:*:*:*:*:*:*:* | ||
< f0b.0e.7eCPE matchmatch criteria | cpe:2.3:o:abbott:anthem_firmware:*:*:*:*:*:*:*:* | ||
< f10.08.6cCPE matchmatch criteria | cpe:2.3:o:abbott:accent_mri_firmware:*:*:*:*:*:*:*:* | ||
< f10.08.6cCPE matchmatch criteria | cpe:2.3:o:abbott:accent_st_firmware:*:*:*:*:*:*:*:* | ||
< f14.07.80CPE matchmatch criteria | cpe:2.3:o:abbott:assurity_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.