CVE-2025-20060 describes a high-severity vulnerability in the Dario Health Android application that allows an unauthenticated attacker to expose cross-user Personal Identifiable Information (PII) and Personal Health Information (PHI) stored in the application's database. With a CVSS score of 7.5, this network-exploitable flaw has high confidentiality impact due to the sensitive nature of the exposed data. There is currently no public exploit code available, nor any evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dario Health | Dario Application Database And Internet-Based Server Infrastructure | All versionsCNA affecteddefault unaffected | |
| Dario Health | USB-C Blood Glucose Monitoring System Starter Kit Android Applications | >= 0, < 5.8.7.0.36CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.