Mira Hormone Monitor, Mira Android App

Plan PatchCVSS 9.8ICS-CERT ICSMA-26-223-01Aug 11, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities in Mira Monitor Firmware and Mira Android/iOS App allow unauthorized access to health profile information, unauthorized modification of health data, denial-of-service conditions, session token disclosure, and account takeover. These include missing authentication, inadequate access controls, hardcoded credentials, and insufficient input validation. Successful exploitation could compromise patient privacy and safety.

What this means
What could happen
An attacker could access patient health records without authorization, modify health data, hijack patient accounts, or disrupt monitoring service. This could lead to incorrect treatment decisions or loss of critical health monitoring during device unavailability.
Who's at risk
Healthcare facilities and individual patients using Mira Hormone Monitor devices for continuous endocrine monitoring. This includes diabetes management centers, fertility clinics, and home-care patients relying on the monitor for medication dosing decisions.
How it could be exploited
An attacker on the internet can send specially crafted requests to the Mira cloud service or mobile app without authentication to read/modify health data, steal session tokens, or cause the device to stop responding. The attack requires no user interaction and exploits weak credential management and missing access controls.
Prerequisites
  • Network access to Mira cloud service or mobile app over the internet
  • No valid user credentials required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)affects patient safety data
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
Mira Monitor Firmware: 1.7.1.471.7.1.47No fix yet
Mira Android App: 4.5.15.44.5.15.4No fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Mira Android app to version 4.5.18 or later
HOTFIXUpdate Mira iOS app to version 3.5.18 or later
HOTFIXEnsure device firmware updates automatically when app connects; manually verify firmware is at version 01.07.01.53 or later after app update
API: /api/v1/advisories/dd51c60d-ea79-498f-aa85-ce54948a0dfa

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Mira Hormone Monitor, Mira Android App | CVSS 9.8 - OTPulse