PT-2018-5613 · Boston Scientific · Zoom Latitude Prm Model 3120

Published

2018-05-01

·

Updated

2019-10-09

·

CVE-2017-14014

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Boston Scientific ZOOM LATITUDE PRM Model 3120
Description: The issue concerns the use of a hard-coded cryptographic key for encrypting Protected Health Information (PHI) before it is transferred to removable media. This could potentially compromise the confidentiality of the data.
Recommendations: For Boston Scientific ZOOM LATITUDE PRM Model 3120, consider updating the device to use dynamically generated cryptographic keys instead of hard-coded ones to enhance the security of PHI encryption. As a temporary workaround, restrict access to removable media to minimize the risk of unauthorized data transfer.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14014

Affected Products

Zoom Latitude Prm Model 3120