CVE-2025-23421 - CVE House
Back to Database
Status published Medium CVE-2025-23421

Qardio iOS and Android applications Files or Directories Accessible to External Parties

Vulnerability Description

An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23421

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Bryan Riggins of Insulet Corporation reported these vulnerabilities to CISA.

Affected Vendor

Affected Software

Heart Health IOS Mobile Application, Heart Health Android Mobile Application
Vulnerable Versions:
2.7.4, 2.5.1

Timeline

Official Publish: February 13th, 2025
Last Modified: February 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses (CWE)