CVE-2020-27276
19.01.2021, 17:15
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.Enginsight
Vendor | Product | Version |
---|---|---|
sooil | anydana-a_firmware | 𝑥 < 3.0 |
sooil | anydana-i_firmware | 𝑥 < 3.0 |
sooil | diabecare_rs_firmware | 𝑥 < 3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration