CVE-2025-20615

Feb. 13, 2025, 10:15 p.m.

6.2
Medium

Description

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal.

Product(s) Impacted

Product Versions
Qardio Arm iOS application

Weaknesses

CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CVSS Score

6.2 / 10

CVSS Data

  • Attack Vector: PHYSICAL
  • Attack Complexity: LOW
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: HIGH
  • Integrity Impact: HIGH
  • Availability Impact: LOW
  • View Vector String

    CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Date

  • Published: Feb. 13, 2025, 10:15 p.m.
  • Last Modified: Feb. 13, 2025, 10:15 p.m.

Status : Undergoing Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

ics-cert@hq.dhs.gov

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.