PT-2020-6904 · Unknown+1 · React Native Bluetooth Scan+1
Thai Duong
·
Published
2020-04-27
·
Updated
2024-08-04
·
CVE-2020-12270
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bluezone version 1.0.0
Description
The issue is related to the use of insufficiently random values in the React Native Bluetooth Scan component of the Bluezone application. This could allow a remote attacker to interfere with COVID-19 contact tracing by using many IDs. The vendor disputes the relevance of this report, stating that the recipient of an alert will know it was a false alert if contact-history comparison fails.
Recommendations
For Bluezone version 1.0.0, consider restricting the use of the React Native Bluetooth Scan component until a patch is available. As a temporary workaround, avoid using the six-character alphanumeric IDs in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bluezone
React Native Bluetooth Scan