#VU56994 Improper validation of integrity check value in ZOOM LATITUDE Programmer/Recorder/Monitor Model 3120 - CVE-2021-38396
Published: October 1, 2021
ZOOM LATITUDE Programmer/Recorder/Monitor Model 3120
Boston Scientific
Description
The vulnerability allows a local attacker to bypass integrity checks.
The vulnerability exists due to the programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker with physical access can install unauthorized software using a specially crafted USB.