PT-2025-7038 · Qardio · Qardio - Heart Health Ios Mobile Application

Bryan Riggins

·

Published

2025-02-13

·

Updated

2025-02-16

·

CVE-2025-24836

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Qardio - Heart Health IOS Mobile Application version 2.7.4
Description: The issue allows an attacker to send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device, preventing it from connecting to a clinician's app to take patient readings and potentially flooding it with requests, resulting in a denial-of-service condition.
Recommendations: For Qardio - Heart Health IOS Mobile Application version 2.7.4, consider disabling the startMeasurement command functionality until a patch is available to prevent exploitation. Restrict access to the device over Bluetooth connections to minimize the risk of denial-of-service attacks.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24836

Affected Products

Qardio - Heart Health Ios Mobile Application