AliveCor KardiaMobile Vulnerabilities
CISA Advisory includes an authentication bypass vulnerability and a missing encryption vulnerability that could allow an attacker to read patient electrocardiography (EKG) results or create a denial-of-service condition
Summary
CISA Advisory includes an authentication bypass vulnerability and a missing encryption vulnerability that could allow an attacker to read patient electrocardiography (EKG) results or create a denial-of-service condition
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The US government agency Cybersecurity and Infrastructure Security Agency (CISA) have released a medical advisory for two vulnerabilities affecting AliveCor Kardiamobile products. The advisory states that successful exploitation of these vulnerabilities could lead to attackers stealing or faking personal cardiograms or enabling a denial-of-service attack. Attackers must be at close range to carry out these attacks.
Vulnerabilities
CVE-2022-40703 - CWE-302 - AUTHENTICATION BYPASS BY ASSUMED-IMMUTABLE DATA
The smartphone application for the affected product is vulnerable to the publicly known “Intent Manipulation” exploit on Android phones. This exploit allows attackers to bypass app authentication and view or alter information in the app. A CVSS v3 base score of 5.2 has been calculated.
CVE-2022-41627 - CWE-311 - MISSING ENCRYPTION OF SENSITIVE DATA
The physical IoT device of the affected product has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient electrocardiography (EKG) results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphone’s ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves. A CVSS v3 base score of 4.8 has been calculated.
Remediation advice
Affected organisations should review CISA Medical Advisory ICSMA-22-298-01 and apply any relevant mitigations.
CISA recommends the following mitigations:
- The Kardia App usage instructions include recommendations for users to use passcode (PIN) or biometric identification for their smartphone devices; such measures greatly reduce the risk of Intent Manipulation.
- AliveCor has acknowledged that the data-over-sound protocol has no encryption and is vulnerable to CVE-[CWE-311], but the circumstances necessary for exploitation are “unlikely.”
- CISA recommends users take defensive measures to minimise the risk of exploitation of this vulnerability.
- CISA reminds organisations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 27 October 2022 12:47 pm