CVE-2021-38394CWE-1278

Missing Protection against Hardware Reverse Engineering Using Integrated Circuit Imaging Techniques for Boston Scientific Zoom Latitude

Medium · published October 4, 2021

CVSS v3.1
6.2
EPSS
0%
Percentile
14.2
In the wild
Unconfirmed
What it is

An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.

The record
Technical detail
CVSS v3.1
6.2 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.00234 · 14.2th percentile
Weakness
CWE-1278 · Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques
Published
2021-10-04T17:34Z
EPSS history
Timeline
  • 04 OCT 17:34Z
    Missing Protection against Hardware Reverse Engineering Using Integrated Circuit Imaging Techniques for Boston Scientific Zoom Latitude
    cvelistv5