← Back to home
ICSMA-20-079-01  ·  Published 2020-03-19  ·  View on CISA ICS-CERT ↗

Insulet Omnipod

CVSS 7.3 HIGH

Risk Summary

Successful exploitation of this vulnerability may allow an attacker to gain access to the affected products to intercept, modify, or interfere with the wireless RF (radio frequency) communications to or from the product. This may allow attackers to read sensitive data, change pump settings, or control insulin delivery.

CVEs (1)

Remediations

  • Insulet recommends patients using the affected products talk to their healthcare provider about the risks of continued use, including the possibility of changing to the latest model with increased cybersecurity protection. Additionally, Insulet recommends all patients take the cybersecurity precautions indicated below.
  • Insulet has released additional patient-focused information.
  • More information is available regarding Insulet 's product security and vulnerability management.

Affected Vendors

Insulet

Affected Products (2)

Insulet · Omnipod Insulin Management System UDI/Model/NDC number ZXP425 (10-Pack) | ZXR425 (10-Pack Canada)
Insulet · Omnipod Insulin Management System Product ID/Reorder number 19191 | 40160

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more