PT-2020-13304 · Australian Government · Covidsafe

Published

2020-05-18

·

Updated

2020-05-20

·

CVE-2020-12859

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions COVIDSafe versions through v1.0.17
Description The issue allows a remote attacker to identify a device model by observing cleartext payload data in the OpenTrace/BlueTrace protocol. This enables re-identification of devices, particularly less common phone models or those in low-density situations.
Recommendations For COVIDSafe versions through v1.0.17, update to a version later than v1.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the cleartext payload data in the OpenTrace/BlueTrace protocol until a patch is available.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12859

Affected Products

Covidsafe