Insufficiently protected credentials in Ypsomed mylife Cloud and Ypsomed mylife App - CVE-2021-27495
Published: July 16, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected software reflects the user password during the login process after redirecting the user from a HTTPS endpoint to a HTTP endpoint. A remote authenticated attacker can disclose sensitive information on the target system.
Affected software
Ypsomed mylife App
How to mitigate CVE-2021-27495
Ypsomed mylife App - update to 1.7.5