CVE-2022-40703
—CVSS 3.1
6.1 medium
EPSS
<1%p25
Published
()
Modified
Description
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
- Vendors
- alivecor
- Products
- kardia
- Weakness
- CWE-302, CWE-287
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.