Medical Devices

Information Disclosure

Lack of Medical data encryption in Dr.Trust ECG/EKG Pen

Lack of Medical data encryption in Dr.Trust ECG/EKG Pen.

5.5
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS42
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-15485
VENDORS
Dr.Trust
PUBLIC EXPLOIT
None indexed
CWE
CWE-312
PRODUCT
ECG/EKG Electrocardiogram Pen
CVSS VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Lack of Medical data encryption in Dr.Trust ECG/EKG Pen.

An issue was discovered on Dr.Trust ECG/EKG Pen. The onboard Flash memory stores ECG/EKG data in cleartext, without integrity protection against tampering. Attacker can remove the Flash chip and tamper with the ECG data.

Vulnerability details

Vulnerability details

CVE-2020-15485
CWE-312
Medium | 5.5

Lack of Medical data encryption in Dr.Trust ECG/EKG Pen. An issue was discovered on Dr.Trust ECG/EKG Pen. The onboard Flash memory stores ECG/EKG data in cleartext, without integrity protection against tampering.

Auth:
Any authenticated user (local access)
Impact:
Sensitive data disclosure
DISCLOSURE

Disclosure timeline

2020-06-22 reported to the vendor

2020-07-22 No response from the vendor and Public disclosure.

Credits

Arun Magesh