Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13702

Опубликовано: 11 июн. 2020
Источник: nvd
CVSS3: 4.3
CVSS3: 10
CVSS2: 6.4
EPSS Низкий

Описание

The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:the_rolling_proximity_identifier_project:the_rolling_proximity_identifier:*:*:*:*:*:*:*:*
Версия до 2020-05-29 (включая)

EPSS

Процентиль: 67%
0.00544
Низкий

4.3 Medium

CVSS3

10 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.

EPSS

Процентиль: 67%
0.00544
Низкий

4.3 Medium

CVSS3

10 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-200