Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 9, 2023
Description
Published by the National Vulnerability Database
Aug 2, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jul 9, 2023
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application layer encryption of the communication protocol between the Ypsomed mylife App and mylife Cloud uses non-random IVs, which allows man-in-the-middle attackers to tamper with messages.
References