Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Javier Junquera Sánchez

Researcher fromUniversity of Alcalá
#21816of 53,635
10.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-25992
4.8
2022-10-27
Alivecor · Kardiamobile · CVE-2022-41627
**Name of the Vulnerable Software and Affected Versions** KardiaMobile (affected versions not specified) **Description** The physical IoT device of the AliveCor's KardiaMobile has no encryption for its data-over-sound protocols. This issue could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphone’s ability to accurately read the data. The attacker must be close (less than 5 feet) to pick up and emit sound waves. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-25481
6.1
2022-10-26
Alivecor · Alivecor Kardia App · CVE-2022-40703
**Name of the Vulnerable Software and Affected Versions** AliveCor Kardia App versions 5.17.1-754993421 and prior **Description** The issue allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app. This is due to authentication bypass by assumed-immutable data. **Recommendations** For AliveCor Kardia App versions 5.17.1-754993421 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.