PatchSiren cyber security CVE debrief
CVE-2025-23405 Dario Health CVE debrief
CVE-2025-23405 is a publicly disclosed issue in the Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android application. CISA’s advisory describes an unauthenticated logging problem that can interfere with log-based metrics and incident response, and that may expose systems to injection attacks such as log injection. The source-assigned CVSS v3.1 score is 5.3 (Medium). Dario Health recommends updating the Android application to the latest version and following basic hardening guidance such as installing from trusted sources, avoiding rooted/jailbroken devices, and avoiding public untrusted networks.
- Vendor
- Dario Health
- Product
- USB-C Blood Glucose Monitoring System Starter Kit Android Applications
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-27
- Original CVE updated
- 2025-02-27
- Advisory published
- 2025-02-27
- Advisory updated
- 2025-02-27
Who should care
Users, administrators, and support teams responsible for the Dario Health Android application and the associated system should pay attention, especially anyone handling app deployment, device hardening, or log-based incident response.
Technical summary
The supplied CISA CSAF advisory (ICSMA-25-058-01) identifies an unauthenticated issue in the Dario Health Android application. The advisory states that the flaw can affect log collection/metrics and incident-response activities and may present a log injection risk. The provided CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, reflecting a network-reachable, no-privileges, no-user-interaction issue with integrity impact only in the source rating.
Defensive priority
Medium. Prioritize the vendor update promptly because the issue is unauthenticated and network-reachable in the source CVSS vector, even though it is not listed as a CISA KEV item.
Recommended defensive actions
- Update the Dario Health Android mobile application to the latest version from a trusted source.
- Verify that app installs and updates come only from trusted sources.
- Avoid using rooted or jailbroken devices with the application.
- Avoid public or otherwise untrusted networks when using the application.
- If you need additional guidance, contact Dario Health through its official contact channel.
Evidence notes
Primary evidence comes from the supplied CISA CSAF source item for ICSMA-25-058-01, which includes the product name, the advisory description, the CVSS v3.1 vector and score, publication timing, and the vendor mitigation guidance. Official reference links in the corpus also include the CVE record and the CISA advisory landing page. No exploit code, proof-of-concept details, or affected-version list beyond the supplied advisory metadata were used.
Official resources
-
CVE-2025-23405 CVE record
CVE.org
-
CVE-2025-23405 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Publicly disclosed by CISA in ICS Medical Advisory ICSMA-25-058-01 on 2025-02-27T07:00:00.000Z.