CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App versionĀ 5.17.1-754993421 and prior
on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kardia | Alivecor | * | 5.17.1-754993421 (including) |