← Back

CVE-2020-12717

nvd nist
Published: May 14, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

Affected (5)

Products: Alberta: Abtracetogether · Gov: Protego Safe · Health: Covidsafe · +1 more
Show all products
1 product
Abtracetogether
1 product
Protego Safe
1 product
Covidsafe
1 product
Tracetogether
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Health
Version 1.0
Version 1.1
All versions

Timeline

No history available yet.