PT-2020-14453 · Dr Trust · Dr Trust Ecg Pen

Arun Magesh

·

Published

2020-08-26

·

Updated

2021-07-21

·

CVE-2020-15486

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dr Trust ECG Pen version 2.00.08
Description An issue allows attackers to access the GATT server of the device without requiring pairing or security. This enables attackers to sniff data being broadcasted during measurements and extract saved data over a Bluetooth connection. Additionally, attackers can launch a man-in-the-middle attack against data integrity.
Recommendations For Dr Trust ECG Pen version 2.00.08, consider disabling Bluetooth LE support until a secure pairing or security mechanism is implemented to prevent unauthorized access. Restrict access to the GATT server to minimize the risk of data sniffing and extraction. Avoid using the device for sensitive measurements until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-15486

Affected Products

Dr Trust Ecg Pen