Improper Authentication in SOOIL Developments Co., Ltd products - CVE-2020-27272
Published: January 14, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the communication protocol of the insulin pump and its mobile applications does not use adequate measures to authenticate the pump before exchanging keys. A remote attacker on the local network can eavesdrop the keys and spoof the pump via Bluetooth Low Energy.
Affected software
AnyDana-i
AnyDana-A
How to mitigate CVE-2020-27272
AnyDana-i - update to 3.0
AnyDana-A - update to 3.0