Medical Devices

Hardware / Firmware Exposure

Authentication & Access Bypass

Lack of Bluetooth LE pairing and access control in Dr.Trust ECG/EKG Pen

Lack of Bluetooth LE pairing and access control on internal data.

6.5
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS43
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-15486
VENDORS
Dr.Trust
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
ECG/EKG Electrocardiogram Pen
CVSS VECTOR
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Lack of Bluetooth LE pairing and access control on internal data.

An issue was discovered on Dr Trust ECG Pen 2.00.08 devices. Because the Bluetooth LE support is implemented without a requirement for pairing or security, any attacker can access the GATT server of the device and can sniff the data being broadcasted while a measurement is being done. Also, saved data can also be extracted over a Bluetooth connection. In addition, an attacker can launch a man-in-the-middle attack against data integrity.

Vulnerability details

Vulnerability details

CVE-2020-15486
Medium | 6.5

Lack of Bluetooth LE pairing and access control on internal data. An issue was discovered on Dr Trust ECG Pen 2.00.08 devices.

Impact:
Sensitive data disclosure
DISCLOSURE

Disclosure timeline

2020-06-22 reported to the vendor

2020-07-22 No response from the vendor and Public disclosure.

References

Credits

Arun Magesh