Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3cc-g2jj-55gh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.

In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.7
nvd
больше 5 лет назад

In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-863