CVE-2020-12717

MEDIUM

COVIDSafe iOS <1.2 - DoS

Title source: llm
STIX 2.1

Description

The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

Exploits (1)

nomisec WORKING POC 1 stars
by wabzqem · poc
https://github.com/wabzqem/covidsafe-CVE-2020-12717-exploit

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0360
EPSS Percentile 87.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (5)
alberta/abtracetogether
gov/protego_safe
health/covidsafe 1.0
health/covidsafe 1.1
tracetogether/tracetogether
Published May 14, 2020
Tracked Since Feb 18, 2026