Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.
The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.
Link | Tags |
---|---|
http://bluetens.com | product |
https://www.secura.com/blog/serious-safety-impact-found-in-bluetooth-low-energy-based-medical-devices | third party advisory exploit technical description |