Improper Authentication in SOOIL Developments Co., Ltd products - CVE-2020-27272

 

Improper Authentication in SOOIL Developments Co., Ltd products - CVE-2020-27272

Published: January 14, 2021


Vulnerability identifier: #VU49520
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27272
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the communication protocol of the insulin pump and its mobile applications does not use adequate measures to authenticate the pump before exchanging keys. A remote attacker on the local network can eavesdrop the keys and spoof the pump via Bluetooth Low Energy.


Affected software

Dana Diabecare RS
AnyDana-i
AnyDana-A

How to mitigate CVE-2020-27272

Install updates from vendor's website.

Dana Diabecare RS - update to 3.0
AnyDana-i - update to 3.0
AnyDana-A - update to 3.0

External References

Related Security Bulletins