CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App versionĀ 5.17.1-754993421 and prior
on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsma-22-298-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-10-26T20:02:06.819Z
Updated: 2024-08-03T12:21:46.771Z
Reserved: 2022-09-29T14:09:27.500Z
Link: CVE-2022-40703
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-26T21:15:10.637
Modified: 2024-11-21T07:21:53.537
Link: CVE-2022-40703
Redhat
No data.