Abbott's vulnerability profile centers on its Accent line of cardiac implantable electronic devices (CIEDs) and related firmware, a specialized medical-device portfolio with limited breadth but significant clinical implications. The recurring exposure involves wireless-communication and authentication weaknesses—cleartext transmission of sensitive information, improper authentication, and missing encryption—that reflect the constraints of implanted-device design and the tension between functionality, power consumption, and security. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abbott over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12712HIGH The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypass | Apr 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-8997HIGH Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerab | Feb 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2017-5149HIGH An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDem | Feb 13, 2017 | 8.9 | 27 | NO | NO |
CVE-2017-12716MEDIUM Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitorin | Apr 25, 2018 | 6.5 | 20 | NO | NO |
CVE-2023-47262MEDIUM The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modified via physical access to an internal serial port. Direct ph | Nov 14, 2023 | 5.2 | 17 | NO | NO |
CVE-2017-12714MEDIUM Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may a | Apr 25, 2018 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abbott.
Media articles that mention a CVE ID that affects a product developed by Abbott — matched by CVE ID, not by vendor name.