CVE-2025-23421 MEDIUM

CVE-2025-23421: Qardio iOS and Android applications Files or Directories Accessible to External Parties

Vendor Qardio
Product Heart Health IOS Mobile Application
Weakness CWE-552 · Files accessible externally
Published February 13, 2025
Last update February 14, 2025

CVSS base score

6.4/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.

Key dates

02Disclosure timeline

February 13, 2025 CVE published
February 14, 2025 Record updated