CVE-2020-8997
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
16/02/2020
Last modified:
28/02/2020
Description
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced in October 2018).
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:abbott:freestyle_libre_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:abbott:freestyle_libre:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page