PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-20060 Dario Health CVE debrief

CVE-2025-20060 is a high-severity issue in the Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android application. According to CISA’s advisory, an attacker could expose cross-user personally identifiable information (PII) and personal health information associated with data transmitted to the Android device via the application database. Dario Health’s published mitigation is to update the Android mobile application to the latest version; the advisory also recommends avoiding rooted or jailbroken devices and avoiding public untrusted networks.

Vendor
Dario Health
Product
USB-C Blood Glucose Monitoring System Starter Kit Android Applications
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-27
Original CVE updated
2025-02-27
Advisory published
2025-02-27
Advisory updated
2025-02-27

Who should care

People using the Dario Health Android application, healthcare and IT teams supporting patients who use the app, and mobile security defenders responsible for protecting health data on Android devices.

Technical summary

The advisory describes a confidentiality issue affecting the Dario Health Android application database and the data it handles on the Android device. The published CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, which aligns with a network-reachable exposure that requires no privileges or user interaction and primarily impacts confidentiality. The source material does not provide affected version details beyond the starter kit Android applications and associated database/server infrastructure.

Defensive priority

High. The issue is rated CVSS 7.5 (HIGH) and involves exposure of PII and personal health information, which increases the impact for users and organizations handling sensitive medical data.

Recommended defensive actions

  • Update the Dario Health Android mobile application to the latest version from trusted sources.
  • Avoid using rooted or jailbroken devices with the application.
  • Avoid public untrusted networks when using the application.
  • If you support affected users, validate that devices and app installs are current and sourced from trusted channels.
  • Contact Dario Health for product-specific guidance if needed.

Evidence notes

This debrief is based on CISA’s CSAF advisory ICSMA-25-058-01 and the supplied CVE metadata. The advisory states that an attacker could expose cross-user PII and personal health information transmitted to the Android device via the Dario Health application database. The same source lists the mitigation to update the Android application to the latest version and recommends avoiding rooted/jailbroken devices and public untrusted networks. No exploit details or affected-version granularity were provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-20060 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-20060

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-20060 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20060

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-058-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-058-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.