An attacker could obtain firmware files and reverse engineer their
intended use leading to loss of confidentiality and integrity of the
hardware devices enabled by the Qardio iOS and Android applications.
Fixes

Solution

No solution given by the vendor.


Workaround

Qardio has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of these affected products are invited to contact Qardio customer support https://www.qardio.com/about-us/#contact for additional information. Users should do the following to help mitigate the risk: * Disable Bluetooth when not in use. * Don't use this device in public or within Bluetooth range of malicious actors. * Only use trusted mobile apps from trusted providers.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}

epss

{'score': 0.00031}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00028}


Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
Description An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.
Title Qardio iOS and Android applications Files or Directories Accessible to External Parties
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-14T15:46:37.858Z

Reserved: 2025-02-10T15:16:25.237Z

Link: CVE-2025-23421

cve-icon Vulnrichment

Updated: 2025-02-14T15:36:25.290Z

cve-icon NVD

Status : Received

Published: 2025-02-13T22:15:12.073

Modified: 2025-02-13T22:15:12.073

Link: CVE-2025-23421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.