# CVE-2021-27499

## Summary

- **CVE ID:** CVE-2021-27499
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-329
- **Published:** Aug 2, 2021
- **Last Modified:** Mar 13, 2026

## Description

Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application layer encryption of the communication protocol between the Ypsomed mylife App and mylife Cloud uses non-random IVs, which allows man-in-the-middle attackers to tamper with messages.

## Affected Products

- n/a — Ypsomed mylife Cloud, mylife Mobile Application (Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5)

## References

- [CNA](https://us-cert.cisa.gov/ics/advisories/icsma-21-196-01)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 27.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._