and passwords in a plist file. This allows an attacker to log in to
production-level development accounts and access an engineering backdoor
in the application. The engineering backdoor allows the attacker to
send hex-based commands over a UI-based terminal.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2177 | The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal. |
Solution
No solution given by the vendor.
Workaround
Qardio has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of these affected products are invited to contact Qardio customer support https://www.qardio.com/about-us/#contact for additional information. Users should do the following to help mitigate the risk: * Disable Bluetooth when not in use. * Don't use this device in public or within Bluetooth range of malicious actors. * Only use trusted mobile apps from trusted providers.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 24 Mar 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qardio
Qardio qardio |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:qardio:qardio:2.7.4:*:*:*:*:iphone_os:*:* | |
| Vendors & Products |
Qardio
Qardio qardio |
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal. | |
| Title | Qardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthorized Actor | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-14T15:46:53.224Z
Reserved: 2025-02-10T15:16:25.268Z
Link: CVE-2025-20615
Updated: 2025-02-14T15:36:28.285Z
Status : Analyzed
Published: 2025-02-13T22:15:11.590
Modified: 2025-03-24T13:39:29.907
Link: CVE-2025-20615
No data.
OpenCVE Enrichment
No data.
EUVD