authority
ACCOUNT_AUTHORITY
Vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:0/DP:3/AT:3/CH:3/SR:4/SX:4/OR:3/EV:3/LS:HISTORICAL CPATH-2026-0001 · WEARABLE HEALTH
ACCOUNT_AUTHORITY authority · Evidence EV:3 (reproduced / report-backed) · Liveness HISTORICAL | CPATH ID | CPATH-2026-0001 |
| CVE(s) | CVE-2025-20615 |
| Device / class | Qardio Arm blood-pressure monitor + iOS app (WEARABLE HEALTH) |
| Vendor | Qardio |
| Dominant consequence | ACCOUNT_AUTHORITY (authority) |
| Paths verdict | CRITICAL (worst of 1 path) |
| Published baseline | v3.1 6.6 MEDIUM CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVDv3.1 6.2 MEDIUM CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L · CISA ICSMA-25-044-01 |
| Baseline relationship | ▼ Paths higher |
| Consequence dimension(s) | #1 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
authority
ACCOUNT_AUTHORITYCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:0/DP:3/AT:3/CH:3/SR:4/SX:4/OR:3/EV:3/LS:HISTORICAL The Paths model rates this CRITICAL because a single static credential shipped in every downloadable app copy yields production engineering authority across the deployed fleet. The published 6.2/6.6 Medium baseline is retained for source review; the Paths driver is fleet-scale authority transfer from a reusable app artifact.
The Qardio Arm iOS app ships static, production-level credentials in a .plist file. Extracting them unlocks an engineering/dev account on api.getqardio.com plus an engineering backdoor that issues raw hex commands to the cardiac-adjacent device over BLE. (CISA ICSMA-25-044-01.)
AV:P (Physical) is the suppressor. FIRST scores Attack Vector relative to the vulnerable component. The analyst modeled the component as “a victim’s installed phone,” requiring physical extraction. But the secret is identical in every downloadable copy — the real component is the distributed app artifact, read from the attacker’s own device. That is AV:N, and reading a file from your own app copy needs no privilege (PR:N). The CWE-359 (“private info exposure”) label also understates a privileged backdoor as a privacy leak.
The Paths model highlights dimension #1 (blast-radius/scale-of-reuse): one extracted credential yields standing engineering-backdoor authority across the deployed fleet. The published baseline depends on a component model that treats the vulnerable artifact as a victim phone (AV:P). The leak is remote and reusable; kinetic BLE delivery remains local.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0001 (“Qardio Arm — static credentials → engineering backdoor”), paths.cfse.ai/CPATH-2026-0001 (published 2026-06-03).