CVE-2025-20615
CVSS 3.1 Score 6.2 of 10 (medium)
Details
Published Feb 13, 2025
CWE ID 359
Summary
CVE-2025-20615 is a vulnerability affecting the Qardio Arm iOS application. The issue arises due to sensitive data, including usernames and passwords, being exposed in a plist file. An attacker can exploit this vulnerability, gaining access to production-level development accounts. Once inside, they can utilize an engineering backdoor that enables sending hex-based commands via a UI-based terminal. This puts user data at risk of unauthorized access and manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share