Security Advisory

CVE-2020-27272

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-01-19 16:18:13
Last updated 2024-08-04 16:11:36
Assigner icscert
State PUBLISHED

Description

SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.