Vulnerabilities > Animas > Onetouch Ping Firmware

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-5686 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
network
animas CWE-287
critical
9.3
2016-10-05 CVE-2016-5086 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
network
animas CWE-287
critical
9.3
2016-10-05 CVE-2016-5085 Use of Insufficiently Random Values vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
network
low complexity
animas CWE-330
7.8
2016-10-05 CVE-2016-5084 Cryptographic Issues vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
animas CWE-310
5.0