CVE Vulnerabilities

CVE-2020-24721

Published: Sep 30, 2020 | Modified: Oct 22, 2020
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disproving an exposure notification, because of the persistent state of a private framework.

Affected Software

Name Vendor Start Version End Version
Exposure_notifications Apple * 1.5 (including)
Exposure_notifications Google * 1.5 (including)

References