CVE-2022-40703
Last modified
CVE-2022-40703 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alivecor | Kardia | <= 5.17.1-754993421 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-298-01Mitigation, Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-298-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40703?
How severe is CVE-2022-40703?
How do I fix CVE-2022-40703?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40698Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability…6.1
- CVE-2022-40699Cross-Site Scripting (XSS) vulnerability in Dario Curvino Ya…6.1
- CVE-2022-4070Insufficient Session Expiration in GitHub repository librenm…9.8
- CVE-2022-40700Server-Side Request Forgery (SSRF) vulnerability in Montonio…9.8
- CVE-2022-40701A directory traversal vulnerability exists in the httpd delf…8.1
- CVE-2022-40702Missing Authorization vulnerability in Zorem Advanced Local …4.3
- CVE-2022-40704A XSS vulnerability was found in phoromatic_r_add_test_detai…6.1
- CVE-2022-40705An Improper Restriction of XML External Entity Reference vul…7.5
- CVE-2022-40707An Out-of-bounds read vulnerability in Trend Micro Deep Secu…3.3
- CVE-2022-40708An Out-of-bounds read vulnerability in Trend Micro Deep Secu…3.3
- CVE-2022-40709An Out-of-bounds read vulnerability in Trend Micro Deep Secu…3.3
- CVE-2022-4071Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2022-40703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
