Lucene search

K
cvelistIcscertCVELIST:CVE-2020-27276
HistoryJan 19, 2021 - 4:18 p.m.

CVE-2020-27276

2021-01-1916:18:20
CWE-290
icscert
www.cve.org
3
sooil developments co ltd
diabecarers
insulin pump
mobile apps
authentication
bluetooth low energy
vulnerability

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

27.0%

SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn’t use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.

CNA Affected

[
  {
    "product": "SOOIL Developments CoLtd DiabecareRS,AnyDana-i,AnyDana-A",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Dana DiabecareRS, AnyDana-i, AnyDana-A  All versions prior to 3.0"
      }
    ]
  }
]

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

27.0%

Related for CVELIST:CVE-2020-27276