CVE-2020-12717

MEDIUM

ABTraceTogether - Denial of Service via Malformed Bluetooth Manufacturer Data

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-12717. PoCs published by wabzqem.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-12717, targeting a Bluetooth Low Energy (BLE) vulnerability in the COVIDSafe iOS app. The exploit involves malformed manufacturer data in BLE advertisements to trigger a crash.

Description

The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

Exploits (1)

nomisec WORKING POC 1 stars
by wabzqem · poc
https://github.com/wabzqem/covidsafe-CVE-2020-12717-exploit

This repository contains a proof-of-concept exploit for CVE-2020-12717, targeting a Bluetooth Low Energy (BLE) vulnerability in the COVIDSafe iOS app. The exploit involves malformed manufacturer data in BLE advertisements to trigger a crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: COVIDSafe iOS app
No auth needed
Prerequisites: Bluetooth Low Energy (BLE) capable device · Node.js environment with @abandonware/bleno module
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0139
EPSS Percentile 69.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (5)
alberta/abtracetogether
gov/protego_safe
health/covidsafe 1.0
health/covidsafe 1.1
tracetogether/tracetogether
Published May 14, 2020
Tracked Since Feb 18, 2026