CVE-2017-12712: Abbott Accent Firmware
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.
Affected products
- Abbott Accent Firmware: before f0b.0e.7e (fixed in f0b.0e.7e)
- Abbott Accent Mri Firmware: before f10.08.6c (fixed in f10.08.6c)
- Abbott Accent St Firmware: before f10.08.6c (fixed in f10.08.6c)
- Abbott Allure Firmware: before f14.07.80 (fixed in f14.07.80)
- Abbott Anthem Firmware: before f0b.0e.7e (fixed in f0b.0e.7e)
- Abbott Assurity Firmware: before f14.07.80 (fixed in f14.07.80)
- Abbott Assurity Mri Firmware: before f17.01.49 (fixed in f17.01.49)
Published 2018-04-25. Last modified 2026-06-17.