CISA Advises on Critical Bluetooth Vulnerability in Pulsetto Vagus Nerve Stimulator
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control system medical advisory regarding a vulnerability in the Pulsetto Vagus Nerve - **Severity:** medium confidence. The firmware of the affected device accepts undisclosed commands over its Bluetooth Low Energy (BLE) interface without authentication or encryption. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify stimulation output settings. The vulnerability affects all versions of the Pulsetto Vagus Nerve Stimulator (vers:all/*) and carries a CVSS 3.1 base score of 8.1 (HIGH). CISA reports no known public exploitation at this time, and states the vulnerability is not exploitable remotely. The vulnerability was reported to CISA by A.C. Buglione and is tracked as CWE-912 (Hidden Functionality).