CVE-2016-5085

Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:animas:onetouch_ping_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:animas:onetouch_ping:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-10-05 10:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-5085

Mitre link : CVE-2016-5085

CVE.ORG link : CVE-2016-5085


JSON object : View

Products Affected

animas

  • onetouch_ping
  • onetouch_ping_firmware
CWE
CWE-330

Use of Insufficiently Random Values