Pulsetto Vagus Nerve Stimulator

Summary

A vulnerability in the Pulsetto Vagus Nerve Stimulator allows attackers to use unauthenticated and unencrypted Bluetooth Low Energy commands to disable safety mechanisms or alter stimulation settings. The firmware accepts hidden commands not used by the mobile app, posing a risk to healthcare and public health critical infrastructure sectors worldwide.

IFF Assessment

FOE

This vulnerability allows an attacker to disable safety mechanisms and modify device settings, which could lead to patient harm and compromise the intended therapeutic function.

Severity

8.1 High

Defender Context

This highlights the risks associated with connected medical devices, especially those using unauthenticated communication channels like BLE. Defenders in healthcare and medical device manufacturing should be aware of the potential for unauthorized command injection in similar devices and advocate for robust authentication and encryption in firmware.

Read Full Story →