CVE-2020-27272
Last modified
CVE-2020-27272 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sooil | Anydana-A Firmware | < 3.0 |
| Sooil | Anydana-I Firmware | < 3.0 |
| Sooil | Diabecare Rs Firmware | < 3.0 |
References
- https://us-cert.cisa.gov/ics/advisories/icsma-21-012-01Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsma-21-012-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27272?
How severe is CVE-2020-27272?
How do I fix CVE-2020-27272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27266In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and A…6.5
- CVE-2020-27267KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and …9.1
- CVE-2020-27268In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and A…6.5
- CVE-2020-27269In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and A…5.7
- CVE-2020-2727Vulnerability in the Oracle VM VirtualBox product of Oracle …6
- CVE-2020-27270SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, …5.7
- CVE-2020-27274Some parsing functions in the affected product do not check …7.5
- CVE-2020-27275Delta Electronics DOPSoft Version 4.0.8.21 and prior is vuln…7.8
- CVE-2020-27276SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A,…5.7
- CVE-2020-27277Delta Electronics DOPSoft Version 4.0.8.21 and prior has a n…7.8
- CVE-2020-27278In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and pri…5.2
- CVE-2020-27279A NULL pointer deference vulnerability has been identified i…7.5
Are you affected by CVE-2020-27272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
