PT-2021-17475 · Ypsomed · Ypsomed Mylife Cloud+1

Dr. Oliver Matula

+3

·

Published

2021-07-30

·

Updated

2021-08-10

·

CVE-2021-27491

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ypsomed mylife Cloud versions prior to 1.7.2 Ypsomed mylife App versions prior to 1.7.5
Description The Ypsomed mylife Cloud discloses password hashes during the registration process.
Recommendations For Ypsomed mylife Cloud versions prior to 1.7.2, update to version 1.7.2 or later. For Ypsomed mylife App versions prior to 1.7.5, update to version 1.7.5 or later.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27491

Affected Products

Ypsomed Mylife App
Ypsomed Mylife Cloud