CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App...
Vulnerability Description
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-40703
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Carlos Cilleruelo Rodríguez
- Javier Junquera Sánchez
Affected Vendor
AliveCor
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.