Vulnerability Description
With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician's app to take patient readings and ostensibly flood it with requests, resulting in a denial-of-service condition.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-044-01
- https://www.qardio.com/about-us/#contact
FAQ
What is CVE-2025-24836?
CVE-2025-24836 is a vulnerability with a CVSS score of 7.1 (HIGH). With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device fro...
How severe is CVE-2025-24836?
CVE-2025-24836 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24836?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.