The Rolling Proximity Identifier used in the Apple/Google Exposure Notification...
Vulnerability Description
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-13702
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200611.pdf
- https://blog.google/documents/70/Exposure_Notification_-_Bluetooth_Specification_v1.2.2.pdf
- https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200616.pdf
- https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200616-2.pdf
- https://github.com/google/exposure-notifications-internals/commit/8f751a666697c3cae0a56ae3464c2c6cbe31b69e
- https://github.com/google/exposure-notifications-internals/commit/8f751a666697
Affected Vendor
the rolling proximity identifier project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.