#VU26245 Improper access control in Omnipod Insulin Management System - CVE-2020-10597
Published: March 20, 2020
Omnipod Insulin Management System
Insulet Corporation
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the wireless RF communication protocol. A local attacker with access to one of the affected insulin pump models can bypass implemented security restrictions and modify and/or intercept data.
The vulnerability can also allow attackers to change pump settings and control insulin delivery.
This vulnerability affects the following versions of the Omnipod Insulin Management System: