Boston Scientific's vulnerability profile concentrates in a narrow line of cardiac rhythm management programmers and monitoring devices—specifically the Zoom Latitude family—which represent critical patient-care infrastructure in implantable device management. The recurring weakness classes, including improper access control, insufficient data authenticity verification, missing encryption of sensitive data, and inadequate protections against hardware reverse engineering, reflect the intersection of wireless connectivity, sensitive patient data, and the physical security demands of implanted medical devices. Current severity, exploitation activity, and detailed exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bostonscientific over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38392HIGH A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to int | Oct 4, 2021 | 7.6 | 24 | NO | NO |
CVE-2021-38398MEDIUM The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit th | Oct 4, 2021 | 6.8 | 22 | NO | NO |
CVE-2021-38396MEDIUM The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness t | Oct 4, 2021 | 6.8 | 22 | NO | NO |
CVE-2021-38400MEDIUM An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for bru | Oct 4, 2021 | 6.8 | 21 | NO | NO |
CVE-2021-38394MEDIUM An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate o | Oct 4, 2021 | 6.4 | 21 | NO | NO |
CVE-2017-14014MEDIUM Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS v | May 1, 2018 | 4.6 | 17 | NO | NO |
CVE-2017-14012MEDIUM Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. | May 1, 2018 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bostonscientific.
Media articles that mention a CVE ID that affects a product developed by Bostonscientific — matched by CVE ID, not by vendor name.