SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsma-21-012-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2021-01-19T16:18:13
Updated: 2024-08-04T16:11:36.580Z
Reserved: 2020-10-19T00:00:00
Link: CVE-2020-27272
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-01-19T17:15:12.613
Modified: 2024-11-21T05:20:58.667
Link: CVE-2020-27272
Redhat
No data.