Impact
The Mira Android companion app version 4.5.15.4 validates a paired hormone analyzer solely by matching a substring of the BLE advertisement name, without any cryptographic authentication, MAC allowlist, or bonded‑identity check. This flaw permits an attacker to spoof a legitimate device, capture the live session token, and inject counterfeit hormone measurements into the victim’s cloud record and clinical trend view, effectively compromising the integrity of medical data and undermining trust in the monitoring system.
Affected Systems
The vulnerability affects the Mira Android App and the Mira hormonal analyzer firmware produced by Quanovate Tech Inc. (operating as Mira / Mira Care). Users of the Android app version 4.5.15.4 (and earlier) are at risk, as are any medical facilities or patients whose devices run firmware that has not been updated through the companion app. The recommended fix involves updating the app to Android v4.5.18 (or iOS v3.5.18 for iPhone users) and ensuring the device firmware is at least v01.07.01.53, which performs an authenticated update when the device is connected.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, classifying it as High risk. The EPSS score is less than 1 %, indicating that exploitation is unlikely but not impossible. It is not listed in the CISA KEV catalog, so no documented attacks are known at this time. Likely, an attacker would need physical proximity or wireless access to the victim’s environment to spoof the BLE advertisement, capture the session token, and inject fabricated data. The impact includes potential clinical misdiagnosis or inappropriate treatment based on falsified measurements.
OpenCVE Enrichment