CVE-2020-12270 describes a weakness in React Native Bluetooth Scan within Bluezone 1.0.0, where its use of six-character alphanumeric IDs could facilitate interference with COVID-19 contact tracing efforts. This medium-severity vulnerability (CVSS 6.5) has an adjacent attack vector and low attack complexity, potentially leading to high confidentiality impact by enabling attackers to generate numerous IDs and disrupt contact history comparisons. Despite the vendor disputing its relevance, the vulnerability is not currently listed in CISA's KEV catalog, lacks known public exploits or Metasploit/Nuclei modules, and has garnered no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:bluezone:bluezone:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.