animas records
4 published records for vendor animas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-310 Cryptographic Issues1
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-5086No exploit | Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.animas · onetouch ping firmware · CWE-287 | Critical9.8 | — | 4.5% | Oct 5, 2016 |
40Plan | CVE-2016-5686No exploit | Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authenticatianimas · onetouch ping firmware · CWE-287 | Critical9.8 | — | 4.5% | Oct 5, 2016 |
31Monitor | CVE-2016-5085No exploit | Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof animas · onetouch ping firmware · CWE-330 | High7.5 | — | 3.9% | Oct 5, 2016 |
31Monitor | CVE-2016-5084No exploit | Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitivanimas · onetouch ping firmware · CWE-310 | High7.5 | — | 2.2% | Oct 5, 2016 |
- CVE-2016-508640Plan
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
CriticalCVSS 9.8No exploitEPSS 5%animas · onetouch ping firmwareOct 5, 2016
- CVE-2016-568640Plan
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authenticati
CriticalCVSS 9.8No exploitEPSS 5%animas · onetouch ping firmwareOct 5, 2016
- CVE-2016-508531Monitor
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof
HighCVSS 7.5No exploitEPSS 4%animas · onetouch ping firmwareOct 5, 2016
- CVE-2016-508431Monitor
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitiv
HighCVSS 7.5No exploitEPSS 2%animas · onetouch ping firmwareOct 5, 2016