CVE-2020-13702

MEDIUM

The Rolling Proximity Identifier < 2020-05-29 - Exposure of Sensitive Information via Bluetooth LE Discovery

Title source: llm
STIX 2.1

Description

The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.

Scores

CVSS v3 4.3
EPSS 0.0217
EPSS Percentile 79.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
the_rolling_proximity_identifier_project/the_rolling_proximity_identifier < 2020-05-29
Published Jun 11, 2020
Tracked Since Feb 18, 2026