This page aggregates publicly disclosed CVE and security risk information related to animas, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2016-5686 | Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol. | [email protected] | 9.8 | 4.52% | 2016-10-05 | 2026-05-06 |
| CVE-2016-5086 | Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks. | [email protected] | 9.8 | 4.52% | 2016-10-05 | 2026-05-06 |
| CVE-2016-5085 | Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake. | [email protected] | 7.5 | 3.86% | 2016-10-05 | 2026-05-06 |
| CVE-2016-5084 | Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network. | [email protected] | 7.5 | 2.22% | 2016-10-05 | 2026-05-06 |