Medical Devices
Hardware / Firmware Exposure
Authentication & Access Bypass
Lack of Bluetooth LE pairing and access control in Dr.Trust ECG/EKG Pen
Lack of Bluetooth LE pairing and access control on internal data.
.png)
Overview
Lack of Bluetooth LE pairing and access control on internal data.
An issue was discovered on Dr Trust ECG Pen 2.00.08 devices. Because the Bluetooth LE support is implemented without a requirement for pairing or security, any attacker can access the GATT server of the device and can sniff the data being broadcasted while a measurement is being done. Also, saved data can also be extracted over a Bluetooth connection. In addition, an attacker can launch a man-in-the-middle attack against data integrity.
Vulnerability details
Lack of Bluetooth LE pairing and access control on internal data. An issue was discovered on Dr Trust ECG Pen 2.00.08 devices.
Disclosure timeline
2020-06-22 reported to the vendor
2020-07-22 No response from the vendor and Public disclosure.
References
2026-06-17 (NVD record)
Credits
Arun Magesh
















