Insufficiently protected credentials in SOOIL Developments Co., Ltd products - CVE-2020-27258
Published: January 13, 2021
Vulnerability details
The vulnerability allows a remot attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficiently protected credentials in the communication protocol of the insulin pump and its mobile applications. A remote attacker on the local network can extract the pump’s keypad lock PIN via Bluetooth Low Energy.
Affected software
AnyDana-i
AnyDana-A
How to mitigate CVE-2020-27258
AnyDana-i - update to 3.0
AnyDana-A - update to 3.0