Vulnerability Description
OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alberta | Abtracetogether | - |
| Health | Covidsafe | <= 1.0.17 |
| Tracetogether | Tracetogether | - |
References
- https://covidsafe.watch/issue-register/cve-2020-12856-long-term-tracking-and-posThird Party Advisory
- https://docs.google.com/document/d/1u5a5ersKBH6eG362atALrzuXo3zuZ70qrGomWVEC27U/Third Party Advisory
- https://github.com/alwentiu/COVIDSafe-CVE-2020-12856/blob/master/README.mdThird Party Advisory
- https://covidsafe.watch/issue-register/cve-2020-12856-long-term-tracking-and-posThird Party Advisory
- https://docs.google.com/document/d/1u5a5ersKBH6eG362atALrzuXo3zuZ70qrGomWVEC27U/Third Party Advisory
- https://github.com/alwentiu/COVIDSafe-CVE-2020-12856/blob/master/README.mdThird Party Advisory
FAQ
What is CVE-2020-12856?
CVE-2020-12856 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and p...
How severe is CVE-2020-12856?
CVE-2020-12856 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12856?
Check the references section above for vendor advisories and patch information. Affected products include: Alberta Abtracetogether, Health Covidsafe, Tracetogether Tracetogether.