7.1
CVSSv3

CVE-2025-24836

CVSSv4: 6.1 | CVSSv3: 7.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.00029 | KEV: Not Included
Published: 13/02/2025 Updated: 13/02/2025

Vulnerability Summary

Bluetooth Denial-of-Service in Medical Device via Continuous Measurement Commands

A vulnerability exists in a medical device where an attacker can use a custom Python script to send repeated startMeasurement commands via an unencrypted Bluetooth connection. By flooding the device with these continuous commands, the attacker can prevent the device from establishing a connection with a clinician's application. This interruption would block the device from transmitting patient readings, effectively creating a denial-of-service situation.

Vulnerable Product Search on Vulmon Subscribe to Product

qardio heart health ios mobile application

qardio heart health android mobile application

qardio qardioarm