« Volver al listado

CVE-2020-27258

Estado: ModificadaMedia (6.5)—

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-27258",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A",
          "versions": [
            {
              "status": "affected",
              "version": "Dana Diabecare RS, AnyDana-i, AnyDana-A  All versions prior to 3.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-19T21:15:14.047",
  "references": [
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsma-21-012-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsma-21-012-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy."
    },
    {
      "lang": "es",
      "value": "En SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i y AnyDana-A, una vulnerabilidad de divulgación de información en el protocolo de comunicación de la bomba de insulina y sus aplicaciones móviles AnyDana-i y AnyDana-A permite a atacantes no autenticados extraer el bloqueo del teclado de la bomba. PIN por medio de Bluetooth Low Energy"
    }
  ],
  "lastModified": "2026-06-17T03:09:04.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sooil:anydana-a:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "712D6D9A-8A9A-412A-94B0-54DCD142C5B1",
              "versionEndExcluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:sooil:anydana-i:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C1AA992-E68C-4A87-8C9A-F487376D8825",
              "versionEndExcluding": "3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sooil:dana_diabecare_rs_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "110D70B7-66A1-4DF0-B080-F0C95FA98B3F",
              "versionEndExcluding": "3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sooil:dana_diabecare_rs:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "84960250-D074-4153-902D-C8C27A948076"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}