Impact
Pulsetto’s firmware accepts a set of hidden commands over its Bluetooth Low Energy interface. The commands are transmitted without authentication or encryption and are not issued by the legitimate companion mobile application. When the device is powered on, it processes these commands, providing an attacker with the ability to alter its operational behavior. This flaw corresponds to CWE‑912, indicating a hard‑coded, undisclosed channel for remote command execution that can compromise device integrity and patient safety.
Affected Systems
The vulnerability affects Pulsetto Vagus Nerve Stimulators. No specific firmware or hardware version information is provided in the CNA data, so all models manufactured by Pulsetto are assumed to be susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation. The device is not listed in the CISA KEV catalog. The attack vector is inferred to require proximity to the device, enabling an attacker to establish a BLE connection while the stimulator is powered on and transmit the hidden commands without needing credentials or encryption. Successful exploitation could lead to unauthorized alteration of therapy settings or device disruption, adversely affecting the patient’s health.
OpenCVE Enrichment