CVE-2021-38392
6.5 MEDIUMA skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemet...
Published: 2021-10-04 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.5 MEDIUM
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
- CWE
- CWE-284
Affected products
| Vendor | Product |
|---|---|
| bostonscientific | zoom_latitude_pogrammer\/recorder\/monitor_3120_firmware |
Description
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2021-38400 — An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially craft... (6.9 MEDIUM)
- CVE-2021-38398 — The affected device uses off-the-shelf software components that contain unpatched vulnerabilities (6.5 MEDIUM)
- CVE-2021-38396 — The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive (6.5 MEDIUM)
- CVE-2021-38394 — An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which cou... (6.2 MEDIUM)
Same CWE
- CVE-2026-47261 — Wasmtime is a runtime for WebAssembly (7.5 HIGH)
- CVE-2026-50892 — Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attacke... (6.5 MEDIUM)
- CVE-2026-50891 — Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a cra... (8.1 HIGH)
- CVE-2026-50886 — Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources vi... (9.1 CRITICAL)
- CVE-2026-50885 — Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive... (7.5 HIGH)