CVE-2020-12270
Summary
| CVE | CVE-2020-12270 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-27 04:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | ** DISPUTED ** React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: the vendor disputes the relevance of this report because the recipient of an F1 alert will know it was a false alert if contact-history comparison fails (i.e., an F0 is not actually part of the contact history obtained from the device of this recipient, or this recipient is not actually part of the contact history obtained from the device of an F0). |
Risk And Classification
Problem Types: CWE-330
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bluezone-app/CHANGELOG.md at afa15fcec391f0edc51d0486a4ca84dd2520bbb3 · BluezoneGlobal/bluezone-app · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| react-native-bluetooth-scan/TraceCovidModule.java at d9ee70fd594093a30e50b6e62a7593a8397c2dab · BluezoneGlobal/react-native-bluetooth-scan · GitHub | MISC | github.com | Third Party Advisory |
| react-native-bluetooth-scan/AndroidManifest.xml at d9ee70fd594093a30e50b6e62a7593a8397c2dab · BluezoneGlobal/react-native-bluetooth-scan · GitHub | MISC | github.com | Third Party Advisory |
| Vietnam's contact tracing app broadcasting a fixed ID | MISC | vnhacker.blogspot.com | Exploit, Third Party Advisory |
| bluezone.ai/CVE | MISC | bluezone.ai | |
| bluezone-app/package.json at afa15fcec391f0edc51d0486a4ca84dd2520bbb3 · BluezoneGlobal/bluezone-app · GitHub | MISC | github.com | Third Party Advisory |
| react-native-bluetooth-scan/BluezonerIdGenerator.java at d9ee70fd594093a30e50b6e62a7593a8397c2dab · BluezoneGlobal/react-native-bluetooth-scan · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.