PT-2021-9161 · Insulet · Insulet Omnipod Insulin Management System

Published

2021-12-01

·

Updated

2023-09-25

·

CVE-2020-10627

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Insulet Omnipod Insulin Management System versions with product ID 19191 and 40160
Description The wireless RF communication protocol used by the Insulet Omnipod Insulin Management System does not properly implement authentication or authorization. This issue could allow an attacker with access to one of the affected insulin pump models to modify and/or intercept data, potentially changing pump settings and controlling insulin delivery.
Recommendations For Insulet Omnipod Insulin Management System versions with product ID 19191 and 40160, consider restricting access to the wireless RF communication protocol until a proper authentication and authorization mechanism is implemented. As a temporary workaround, restrict physical access to the affected insulin pump models to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2020-10627

Affected Products

Insulet Omnipod Insulin Management System