Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Animas Subscribe
Filtered by product Onetouch Ping
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-5084 1 Animas 2 Onetouch Ping, Onetouch Ping Firmware 2016-12-23 5.0 MEDIUM 7.5 HIGH
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
CVE-2016-5085 1 Animas 2 Onetouch Ping, Onetouch Ping Firmware 2016-12-23 7.8 HIGH 7.5 HIGH
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
CVE-2016-5086 1 Animas 2 Onetouch Ping, Onetouch Ping Firmware 2016-12-23 9.3 HIGH 9.8 CRITICAL
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
CVE-2016-5686 1 Animas 2 Onetouch Ping, Onetouch Ping Firmware 2016-11-28 9.3 HIGH 9.8 CRITICAL
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.