#VU105339 Information disclosure in USB-C Blood Glucose Monitoring System Starter Kit Android Applications and Dario Application Database and Internet-based Server Infrastructure - CVE-2025-20060
Published: March 5, 2025
USB-C Blood Glucose Monitoring System Starter Kit Android Applications
Dario Application Database and Internet-based Server Infrastructure
DarioHealth Corp
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can expose cross-user Personal Identifiable Information (PII) and personal health information transmitted to the Android device via the Dario Health application database.