{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-30T16:50:01.367","vulnerabilities":[{"cve":{"id":"CVE-2020-10627","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2021-12-01T16:15:07.390","lastModified":"2024-11-21T04:55:43.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery."},{"lang":"es","value":"La bomba de insulina Insulet Omnipod Insulin Management System, con ID de producto 19191 y 40160, está diseñada para comunicarse mediante RF inalámbrica con un dispositivo de administración personal de la diabetes fabricado por Insulet. Este protocolo de comunicación de RF inalámbrica no implementa apropiadamente la autenticación o la autorización. Un atacante con acceso a uno de los modelos de bomba de insulina afectados podría ser capaz de modificar y/o interceptar datos. Esta vulnerabilidad también podría permitir a atacantes cambiar la configuración de la bomba y controlar la administración de insulina"}],"metrics":{"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.5,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:P/A:N","baseScore":4.8,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.5,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:insulet:omnipod_insulin_management_system_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"FC41AB2D-AB47-41B7-AEBA-AB4C0A8608A5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:insulet:omnipod_insulin_management_system:19191:*:*:*:*:*:*:*","matchCriteriaId":"98184BD3-4593-4194-A00C-9C064BE96144"},{"vulnerable":false,"criteria":"cpe:2.3:h:insulet:omnipod_insulin_management_system:40160:*:*:*:*:*:*:*","matchCriteriaId":"7AF53C0A-02F1-4F3C-996F-E0E5269034C2"}]}]}],"references":[{"url":"https://us-cert.cisa.gov/ics/advisories/icsma-20-079-01","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.myomnipod.com/security-bulletins","source":"ics-cert@hq.dhs.gov","tags":["Vendor Advisory"]},{"url":"https://us-cert.cisa.gov/ics/advisories/icsma-20-079-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.myomnipod.com/security-bulletins","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}