An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications…
mitre·CWE-294·Published 2020-10-07
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflipping to amplify a contamination attack. This can cause metadata deanonymization and risk-score inflation. NOTE: the vendor's position is "We do not believe that TX power authentication would be a useful defense against relay attacks.
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflipping to amplify a contamination attack. This can cause metadata deanonymization and risk-score inflation. NOTE: the vendor's position is "We do not believe that TX power authentication would be a useful defense against relay attacks.
**EN DISPUTA** Se detectó un problema en el protocolo GAEN (también se conoce como Google/Apple Exposure Notifications) hasta el 05/10/2020, tal como es usado en las aplicaciones COVID-19 en Android e iOS. El bloque de metadatos cifrados con un valor TX carece de un checksum, permitiendo a bitflipping amplificar un ataque de contaminación. Esto puede causar una desanonimización de los metadatos y la inflación de la puntuación de riesgo. NOTA: la posición del proveedor es "No creemos que la autenticación de energía TX sea una defensa útil contra los ataques de retransmisión"
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 2.6 | 4.9 | 2.9 | AV:N/AC:H/Au:N/C:N/I:P/A:N |
| 3.1 | Primary | NVD | 5.9 | 2.2 | 3.6 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |