Insufficiently protected credentials in SOOIL Developments Co., Ltd products - CVE-2020-27270
Published: January 14, 2021
Vulnerability details
The vulnerability allows a remot attacker to gain access to potentially sensitive information.
The vulnerability exists due to the communication protocol of the insulin pump and its mobile applications does not use adequate measures to protect encryption keys in transit. A remote attacker on the local network can sniff the keys via Bluetooth Low Energy.
Affected software
AnyDana-i
AnyDana-A
How to mitigate CVE-2020-27270
AnyDana-i - update to 3.0
AnyDana-A - update to 3.0