Vulnerability identifier: #VU49509
Vulnerability risk: Low
Exploitation vector: Local
Exploit availability: No
Vendor: SOOIL Developments Co., Ltd
The vulnerability allows a local attacker to gain full access to vulnerable system.
The vulnerability exists due to a hard-coded physician PIN in the physician menu of the insulin pump. An attacker with physical access can change insulin therapy settings.
Install update from vendor's website.
Vulnerable software versions
Dana Diabecare RS: before 3.0
AnyDana-i: before 3.0
AnyDana-A: before 3.0
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.