Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.
References
Link | Resource |
---|---|
http://bluetens.com | Product |
https://www.secura.com/blog/serious-safety-impact-found-in-bluetooth-low-energy-based-medical-devices | Exploit Technical Description Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-08-03 02:15
Updated : 2023-08-05 03:48
NVD link : CVE-2023-26979
Mitre link : CVE-2023-26979
CVE.ORG link : CVE-2023-26979
JSON object : View
Products Affected
bluetens
- bluetensq
CWE
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel