CVE-2025-24843 describes an insecure file retrieval process that could lead to file manipulation, impacting the stability, confidentiality, integrity, authenticity, and attestation of stored data. With a CVSS score of 5.1 (Medium), this vulnerability has a local attack vector and low attack complexity, potentially resulting in low impact to integrity and availability. There are currently no affected products specified, and it is not listed on the CISA KEV catalog, indicating no active exploitation. Furthermore, there is no public exploit code available, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dario Health | Dario Application Database And Internet-Based Server Infrastructure | All versionsCNA affecteddefault unaffected | |
| Dario Health | USB-C Blood Glucose Monitoring System Starter Kit Android Applications | >= 0, < 5.8.7.0.36CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.