PT-2020-6904 · Unknown+1 · React Native Bluetooth Scan+1

Thai Duong

·

Published

2020-04-27

·

Updated

2024-08-04

·

CVE-2020-12270

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bluezone version 1.0.0
Description The issue is related to the use of insufficiently random values in the React Native Bluetooth Scan component of the Bluezone application. This could allow a remote attacker to interfere with COVID-19 contact tracing by using many IDs. The vendor disputes the relevance of this report, stating that the recipient of an alert will know it was a false alert if contact-history comparison fails.
Recommendations For Bluezone version 1.0.0, consider restricting the use of the React Native Bluetooth Scan component until a patch is available. As a temporary workaround, avoid using the six-character alphanumeric IDs in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

BDU:2023-05492
CVE-2020-12270

Affected Products

Bluezone
React Native Bluetooth Scan