CVE-2025-24849 Details
Description
Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.
A vulnerability exists in the Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application, all versions through 5.8.7.0.36, due to a lack of encryption for sensitive data in transit. This vulnerability could lead to unauthorized manipulation or exposure of private personal information, including health data, transmitted to the Android device via the Dario Health application database. The issue is compounded by the fact that the Dario Health Internet-based server infrastructure, which supports the application, is also vulnerable, creating a potential risk for data interception or alteration.
Users are advised to update the Dario Health Android mobile application to the latest version. For more information, contact Dario Health directly. CISA recommends minimizing network exposure for all control system devices, locating control system networks behind firewalls, and using secure remote access methods, such as VPNs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 28, 2025CISA-ADP
Assessed Feb 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01 | [email protected] | AdvisoryBundleRemedy |
| https://www.dariohealth.com/contact/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dario Health USB-C Blood Glucose Monitoring System Starter Kit | <= 5.8.7.0.36 |
CPE
Remediation
| |
| Dario Health Application Database | All versions |
CPE
Remediation
| |
| Dario Health Internet-based Server Infrastructure | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 28, 2025 | New CVE Received | [email protected] |
Volerion