Vulnerability Details CVE-2020-27269
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.3%
CVSS Severity
CVSS v3 Score 5.7
CVSS v2 Score 2.9
Products affected by CVE-2020-27269
-
cpe:2.3:h:sooil:anydana-a:-
-
cpe:2.3:h:sooil:anydana-i:-
-
cpe:2.3:h:sooil:diabecare_rs:-
-
cpe:2.3:o:sooil:anydana-a_firmware:*
-
cpe:2.3:o:sooil:anydana-i_firmware:*
-
cpe:2.3:o:sooil:diabecare_rs_firmware:*