Impact
The vulnerability allows attackers to brute‑force user accounts through the Mira cloud authentication endpoints because rate limiting, per‑IP throttling, and account lockout are not enforced. This flaw, classified as CWE‑307, enables an adversary to obtain unauthorized access, potentially exposing sensitive health data or allowing control of the device.
Affected Systems
The flaw affects the Mira Android app and the Mira firmware device from Quanovate Tech Inc. (operating as Mira / Mira Care). All versions prior to the latest releases listed—iOS v3.5.18, Android v4.5.18, and firmware v01.07.01.53—are vulnerable; newer releases contain the fix.
Risk and Exploitability
The CVSS score of 6.9 signals moderate severity. The EPSS score is below 1%, indicating a low likelihood of current exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. However, the attack vector is inferred to be remote access to the authentication service over the internet, and a determined attacker could exploit the lack of rate limiting to compromise accounts.
OpenCVE Enrichment