#VU49510 Insufficiently protected credentials in SOOIL Developments Co., Ltd products - CVE-2020-27258
Published: January 13, 2021
Dana Diabecare RS
AnyDana-i
AnyDana-A
SOOIL Developments Co., Ltd
Description
The vulnerability allows a remot attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficiently protected credentials in the communication protocol of the insulin pump and its mobile applications. A remote attacker on the local network can extract the pump’s keypad lock PIN via Bluetooth Low Energy.