Sooil manufactures a focused line of insulin infusion pump devices, particularly the AnyDana series, which deliver critical medication to patients with diabetes and represent a specialized medical-device footprint. The vendor's vulnerability profile centers on authentication and credential-handling weaknesses across its pump firmware and companion applications, including insufficiently protected credentials, replay attacks, spoofing vectors, and client-side security enforcement that bypass backend protections—classes typical of medical-device ecosystems where legacy firmware and constrained deployment models limit patching velocity. Defenders managing these devices should prioritize network segmentation and monitor for firmware updates from the vendor; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sooil over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27264HIGH In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use determi | Jan 19, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-27256MEDIUM In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to | Jan 19, 2021 | 6.8 | 23 | NO | NO |
CVE-2020-27268MEDIUM In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications al | Jan 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-27266MEDIUM In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications al | Jan 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-27258MEDIUM In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i an | Jan 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-27272MEDIUM SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to auth | Jan 19, 2021 | 5.7 | 21 | NO | NO |
CVE-2020-27270MEDIUM SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect enc | Jan 19, 2021 | 5.7 | 21 | NO | NO |
CVE-2020-27269MEDIUM In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks repla | Jan 19, 2021 | 5.7 | 20 | NO | NO |
CVE-2020-27276MEDIUM SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures | Jan 19, 2021 | 5.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sooil.
Media articles that mention a CVE ID that affects a product developed by Sooil — matched by CVE ID, not by vendor name.