CVE-2020-12717
MEDIUMABTraceTogether - Denial of Service via Malformed Bluetooth Manufacturer Data
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-12717. PoCs published by wabzqem.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-12717, targeting a Bluetooth Low Energy (BLE) vulnerability in the COVIDSafe iOS app. The exploit involves malformed manufacturer data in BLE advertisements to trigger a crash.
Description
The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2020-12717, targeting a Bluetooth Low Energy (BLE) vulnerability in the COVIDSafe iOS app. The exploit involves malformed manufacturer data in BLE advertisements to trigger a crash.
References (1)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H