Skip to content

Latest commit

 

History

History
29 lines (14 loc) · 1.18 KB

CWE-319.md

File metadata and controls

29 lines (14 loc) · 1.18 KB

Vulnerability Report: Pops Rebel Bluetooth Glucose Monitoring System

Status: FDA cleared

Vulnerability Details

An unauthenticated remote attacker in BLE proximity can remotely aggregate unencrypted diabetic data from the Pops Rebel Bluetooth Glucose Monitoring System for users of Pops Rebel version 5.0 for Android. This vulnerability is classified as CWE-319: Cleartext Transmission of Sensitive Information.

Pops Rebel Glucose Monitoring System

Vulnerability Evidence

Here are some images and details related to the vulnerability:

The static code analysis below depicts the correlation between the app source code and an actual BLE capture in Wireshark:

Static Code Analysis

This issue was reported to the vendor, POPS! Diabetes Care Inc., in April 2023.

Vendor Notification

Discoverer

The vulnerability was discovered by Edward Warren.