PatchSiren

Abbott CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Abbott CVE published 2017-02-13

CVE-2017-5149

CVE-2017-5149 describes a man-in-the-middle risk in St. Jude Medical/Abbott Merlin@home because the transmitter does not verify the identities of the endpoints on its communication channel with Merlin.net. That weakness can let an attacker access or influence communications between the device and the service. The CVE was published on 2017-02-13.