PT-2021-11353 · Unknown+2 · Diabecare Rs+2
Birk Kauer
+3
·
Published
2021-01-19
·
Updated
2021-10-19
·
CVE-2020-27266
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Diabecare RS (affected versions not specified)
AnyDana-i (affected versions not specified)
AnyDana-A (affected versions not specified)
Description:
A client-side control issue in the insulin pump and its mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy. This affects the Diabecare RS, AnyDana-i, and AnyDana-A products.
Recommendations:
For Diabecare RS, consider disabling Bluetooth Low Energy connectivity until a patch is available.
For AnyDana-i, restrict access to the mobile application's authentication features to minimize the risk of exploitation.
For AnyDana-A, avoid using the device in areas where physically proximate attackers could bypass user authentication checks via Bluetooth Low Energy until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anydana-A
Anydana-I
Diabecare Rs