Impact
A remote unauthenticated attacker within Bluetooth Low Energy (BLE) proximity can silently rebind the Mira hormone monitor device to an attacker‑controlled account, exposing stored hormone measurements in clear text, inducing a denial‑of‑service via malformed commands, and passively tracking the user through a static random BLE address that never changes. The flaw stems from missing authentication controls, a weakness identified as CWE‑306.
Affected Systems
The affected software is the Mira Android App and Mira firmware (v1.7.1.47 build 01070147) released by Quanovate Tech Inc., operating as Mira / Mira Care. The latest app versions are Android v4.5.18 and iOS v3.5.18, while the patched firmware is v01.07.01.53. These devices communicate over BLE in the 10–30 meter range.
Risk and Exploitability
The CVSS score of 8.7 marks this vulnerability as high severity. While the EPSS score is reported as less than 1 %, indicating a low overall exploitation probability, the attack vector is fairly straightforward for an attacker within range: no authentication is required, a simple BLE connection can rebind the device, and the attacker can immediately obtain sensitive data. Because the vulnerability is not listed in the CISA KEV catalog, no known widespread attacks have been reported yet, but the potential impact on personal health data and device integrity warrants rapid remediation.
OpenCVE Enrichment