Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5941 | Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise. |
Solution
Dario Health recommends users update their Dario Health Android mobile application to the latest version. No other actions are required by users.
Workaround
Dario Health recommends users perform the following mitigations: * Update the application from trusted sources. * Don't use rooted/jailbroken devices. * Avoid public untrusted network. * For more information contact Dario Health https://www.dariohealth.com/contact/ directly.
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise. | |
| Title | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Sensitive Cookie Without 'HttpOnly' Flag | |
| Weaknesses | CWE-1004 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-28T18:19:26.403Z
Reserved: 2025-01-27T21:33:08.452Z
Link: CVE-2025-24318
Updated: 2025-02-28T18:19:21.613Z
Status : Received
Published: 2025-02-28T17:15:16.937
Modified: 2025-02-28T17:15:16.937
Link: CVE-2025-24318
No data.
OpenCVE Enrichment
No data.
EUVD