The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics. | |
| Title | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-12T12:57:16.516Z
Reserved: 2026-08-03T16:54:56.490Z
Link: CVE-2026-64934
Updated: 2026-08-12T12:57:13.303Z
Status : Received
Published: 2026-08-11T22:18:41.897
Modified: 2026-08-12T14:18:28.447
Link: CVE-2026-64934
No data.
OpenCVE Enrichment
Updated: 2026-08-12T19:45:08Z