CVE-2021-38394 describes a physical access vulnerability affecting Boston Scientific ZOOM Latitude Programmers/Recorders/Monitors (models 3120 and its firmware). An attacker with physical access can extract and reverse engineer the hardware key validation binary, potentially enabling the creation of duplicate hardware keys to access special device settings. Rated Medium severity (CVSS 6.4), this vulnerability requires physical access and high attack complexity but could lead to high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:bostonscientific:zoom_latitude_pogrammer\/recorder\/monitor_3120_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.