Missing Encryption of Sensitive Data
CVE-2023-30561
Summary
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
- LOW
- PHYSICAL
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-311 - Missing Encryption of Sensitive Data
The software does not encrypt sensitive or critical information before storage or transmission.
References
Advisory Timeline
- Published