CVE-2025-23405

MEDIUM

Unauthenticated Log Effects - Info Disclosure

Title source: llm
STIX 2.1

Description

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-117
Status published
Products (2)
Dario Health/Dario Application Database and Internet-based Server Infrastructure All versions
Dario Health/USB-C Blood Glucose Monitoring System Starter Kit Android Applications < 5.8.7.0.36
Published Feb 28, 2025
Tracked Since Feb 18, 2026