PT-2016-6640 · Johnson & Johnson · Animas Onetouch Ping

Jay Radcliffe

·

Published

2016-10-05

·

Updated

2016-11-28

·

CVE-2016-5686

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Johnson & Johnson Animas OneTouch Ping devices (affected versions not specified)
Description The issue concerns the mishandling of acknowledgements in the custom communication protocol used by the devices, making it easier for remote attackers to bypass authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5686

Affected Products

Animas Onetouch Ping