6.2
CVSSv3

CVE-2025-20615

CVSSv4: NA | CVSSv3: 6.2 | CVSSv2: NA | VMScore: 720 | EPSS: 0.00021 | KEV: Not Included
Published: 13/02/2025 Updated: 13/02/2025

Vulnerability Summary

Qardio Arm iOS App Authentication Bypass via Sensitive Data Exposure

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an malicious user to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the malicious user to send hex-based commands over a UI-based terminal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qardio heart health ios mobile application