The Qardio Arm iOS application exposes sensitive data such as usernames
and passwords in a plist file. This allows an attacker to log in to
production-level development accounts and access an engineering backdoor
in the application. The engineering backdoor allows the attacker to
send hex-based commands over a UI-based terminal.
Fixes

Solution

No solution given by the vendor.


Workaround

Qardio has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of these affected products are invited to contact Qardio customer support https://www.qardio.com/about-us/#contact for additional information. Users should do the following to help mitigate the risk: * Disable Bluetooth when not in use. * Don't use this device in public or within Bluetooth range of malicious actors. * Only use trusted mobile apps from trusted providers.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}

epss

{'score': 0.00031}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00034}

epss

{'score': 0.00027}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Qardio
Qardio qardio
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:qardio:qardio:2.7.4:*:*:*:*:iphone_os:*:*
Vendors & Products Qardio
Qardio qardio

Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
Description The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal.
Title Qardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthorized Actor
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-14T15:46:53.224Z

Reserved: 2025-02-10T15:16:25.268Z

Link: CVE-2025-20615

cve-icon Vulnrichment

Updated: 2025-02-14T15:36:28.285Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-13T22:15:11.590

Modified: 2025-03-24T13:39:29.907

Link: CVE-2025-20615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.