PT-2021-11353 · Unknown+2 · Diabecare Rs+2

Birk Kauer

+3

·

Published

2021-01-19

·

Updated

2021-10-19

·

CVE-2020-27266

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Diabecare RS (affected versions not specified) AnyDana-i (affected versions not specified) AnyDana-A (affected versions not specified)
Description: A client-side control issue in the insulin pump and its mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy. This affects the Diabecare RS, AnyDana-i, and AnyDana-A products.
Recommendations: For Diabecare RS, consider disabling Bluetooth Low Energy connectivity until a patch is available. For AnyDana-i, restrict access to the mobile application's authentication features to minimize the risk of exploitation. For AnyDana-A, avoid using the device in areas where physically proximate attackers could bypass user authentication checks via Bluetooth Low Energy until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27266

Affected Products

Anydana-A
Anydana-I
Diabecare Rs