ID |
CVE-2020-27272
|
Sažetak |
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE. |
Reference |
|
CVSS |
Base: | 2.9 |
Impact: | 2.9 |
Exploitability: | 5.5 |
|
Pristup |
Vektor | Složenost | Autentikacija |
ADJACENT_NETWORK |
MEDIUM |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
NONE |
NONE |
|
CVSS vektor |
AV:A/AC:M/Au:N/C:P/I:N/A:N |
Zadnje važnije ažuriranje |
21-07-2021 - 11:39 |
Objavljeno |
19-01-2021 - 17:15 |