{ "CVE_data_meta": { "ASSIGNER": "ics-cert@hq.dhs.gov", "ID": "CVE-2020-10627", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Omnipod Insulin Management System", "version": { "version_data": [ { "version_affected": "=", "version_value": "19191" }, { "version_affected": "=", "version_value": "40160" }, { "version_affected": "=", "version_value": "ZXP425" }, { "version_affected": "=", "version_value": "ZXR425" } ] } } ] }, "vendor_name": "Insulet" } ] } }, "credit": [ { "lang": "eng", "value": "Thirdwayv Inc. reported this vulnerability to Insulet" } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "LOW", "baseScore": 7.3, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-284 Improper Access Control" } ] } ] }, "references": { "reference_data": [ { "refsource": "MISC", "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-079-01", "name": "https://us-cert.cisa.gov/ics/advisories/icsma-20-079-01" }, { "refsource": "MISC", "url": "https://www.myomnipod.com/security-bulletins", "name": "https://www.myomnipod.com/security-bulletins" } ] }, "source": { "advisory": "ICSMA-20-079-01", "discovery": "EXTERNAL" }, "work_around": [ { "lang": "eng", "value": "Insulet recommends patients using the affected products talk to their healthcare provider about the risks of continued use, including the possibility of changing to the latest model with increased cybersecurity protection.\nAdditionally, Insulet recommends all patients take the cybersecurity precautions indicated below.\n\n Do not connect to or allow any third-party devices to be connected to or use any software not authorized by Insulet.\n Maintain tight physical control of the pump and devices connected to the pump.\n Be attentive to pump notifications, alarms, and alerts.\n Immediately cancel any unintended boluses (a single dose of insulin administered all at once).\n Monitor blood glucose levels closely and act as appropriate.\n Get medical help immediately when experiencing symptoms of severe hypoglycemia or diabetic ketoacidosis or if you suspect insulin pump settings or insulin delivery has changed unexpectedly.\n\nInsulet has released additional patient-focused information: https://www.myomnipod.com/security-bulletins \n\nMore information is available regarding Insulet\u2019s product security and vulnerability management: https://www.myomnipod.com/product-security " } ] }