Johnson & Johnson
Products
4- 4 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-5686 | Cri | 0.64 | 9.8 | 0.05 | Oct 5, 2016 | Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol. | ||
| CVE-2016-5086 | Cri | 0.64 | 9.8 | 0.05 | Oct 5, 2016 | Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks. | ||
| CVE-2016-5085 | Hig | 0.49 | 7.5 | 0.04 | Oct 5, 2016 | Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake. | ||
| CVE-2016-5084 | Hig | 0.49 | 7.5 | 0.02 | Oct 5, 2016 | Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network. | ||
| CVE-2017-14018 | Med | 0.31 | 4.8 | 0.00 | Dec 5, 2017 | An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products… | ||
| CVE-2026-57913 | 0.00 | — | 0.00 | Jun 26, 2026 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts. | |||
| CVE-2026-57912 | 0.00 | — | 0.00 | Jun 26, 2026 | Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers. |
- risk 0.64cvss 9.8epss 0.05
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
- risk 0.64cvss 9.8epss 0.05
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
- risk 0.49cvss 7.5epss 0.04
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
- risk 0.49cvss 7.5epss 0.02
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
- risk 0.31cvss 4.8epss 0.00
An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products…
- CVE-2026-57913Jun 26, 2026risk 0.00cvss —epss 0.00
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
- CVE-2026-57912Jun 26, 2026risk 0.00cvss —epss 0.00
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.