CVE-2016-5085 describes a critical vulnerability in Johnson & Johnson Animas OneTouch Ping insulin pumps and their firmware. The flaw stems from improper random number generation, allowing remote attackers to spoof meters by sniffing network traffic and then engaging in an authentication handshake. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk with a low attack complexity and the potential for high integrity impact, specifically allowing unauthorized control over the device. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, highlighting its potential for harm.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:animas:onetouch_ping_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.