High severity8.9NVD Advisory· Published Feb 13, 2017· Updated May 13, 2026
CVE-2017-5149
CVE-2017-5149
Description
An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical's web site, Merlin.net, are not verified. This may allow a man-in-the-middle attacker to access or influence communications between the identified endpoints.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/95331nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSMA-17-009-01AnvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.