CyberRota Analysis
AI-GeneratedThe firmware of the Pulsetto Vagus Nerve Stimulator is vulnerable due to its acceptance of unauthenticated and unencrypted commands via its Bluetooth Low Energy interface, which can be exploited when the device is powered on. This could allow an attacker to manipulate the device without user consent, potentially leading to unauthorized control or disruption of its intended medical functions. Manufacturers and healthcare providers utilizing this device should prioritize addressing this vulnerability to ensure patient safety and device integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.