|
210371
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measur…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-27269
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210372
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-27268
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210373
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-287
Improper Authentication
|
CVE-2020-27266
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210374
|
8.8 |
HIGH
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27264
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210375
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-i anydana-a dana_diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27258
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210376
|
6.8 |
MEDIUM
Physics
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin ther…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-27256
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210377
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-27276
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210378
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump b…
|
NVD-CWE-noinfo
|
CVE-2020-27272
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210379
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in tra…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27270
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210380
|
6.1 |
MEDIUM
Network
|
eclipse
|
hawkbit
|
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST reques…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27219
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|