Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Exposure Notifications Project Subscribe
Filtered by product Exposure Notifications
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24722 1 Exposure Notifications Project 1 Exposure Notifications 2020-10-22 2.6 LOW 5.9 MEDIUM
** DISPUTED ** An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflipping to amplify a contamination attack. This can cause metadata deanonymization and risk-score inflation. NOTE: the vendor's position is "We do not believe that TX power authentication would be a useful defense against relay attacks."