漏洞标题
Qardio Heart Health IOS及Android应用和QardioARM A100未捕获异常漏洞
漏洞描述信息
攻击者可以通过精心制作的Python脚本,向受影响设备发送一系列的连续startMeasurement命令。这些命令是通过未加密的蓝牙连接发送的。这将阻止设备连接到临床医生的应用程序以获取患者数据,并且看似会用请求淹没设备,导致拒绝服务(Denial-of-Service)条件。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
未加控制的资源消耗(资源穷尽)
漏洞标题
Qardio Heart Health IOS and Android Application and QardioARM A100 Uncaught Exception
漏洞描述信息
With a specially crafted Python script, an attacker could send
continuous startMeasurement commands over an unencrypted Bluetooth
connection to the affected device. This would prevent the device from
connecting to a clinician's app to take patient readings and ostensibly
flood it with requests, resulting in a denial-of-service condition.
CVSS信息
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
漏洞类别
未捕获的异常