Pulsetto Vagus Nerve Stimulator
Summary
A vulnerability in the Pulsetto Vagus Nerve Stimulator allows attackers to use unauthenticated and unencrypted Bluetooth Low Energy commands to disable safety mechanisms or alter stimulation settings. The firmware accepts hidden commands not used by the mobile app, posing a risk to healthcare and public health critical infrastructure sectors worldwide.
IFF Assessment
This vulnerability allows an attacker to disable safety mechanisms and modify device settings, which could lead to patient harm and compromise the intended therapeutic function.
Severity
Defender Context
This highlights the risks associated with connected medical devices, especially those using unauthenticated communication channels like BLE. Defenders in healthcare and medical device manufacturing should be aware of the potential for unauthorized command injection in similar devices and advocate for robust authentication and encryption in firmware.