PT-2025-7038 · Qardio · Qardio - Heart Health Ios Mobile Application
Bryan Riggins
·
Published
2025-02-13
·
Updated
2025-02-16
·
CVE-2025-24836
CVSS v3.1
7.1
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Qardio - Heart Health IOS Mobile Application version 2.7.4
Description:
The issue allows an attacker to send continuous
startMeasurement commands over an unencrypted Bluetooth connection to the affected device, preventing it from connecting to a clinician's app to take patient readings and potentially flooding it with requests, resulting in a denial-of-service condition.Recommendations:
For Qardio - Heart Health IOS Mobile Application version 2.7.4, consider disabling the
startMeasurement command functionality until a patch is available to prevent exploitation. Restrict access to the device over Bluetooth connections to minimize the risk of denial-of-service attacks.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qardio - Heart Health Ios Mobile Application