{"id":"CVE-2020-13702","details":"The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.","modified":"2026-09-12T11:30:20.721259722Z","published":"2020-06-11T19:15:10.073Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"the_rolling_proximity_identifier_project:the_rolling_proximity_identifier","cpes":["cpe:2.3:a:the_rolling_proximity_identifier_project:the_rolling_proximity_identifier:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2020-05-29"}]},{"extracted_events":[{"fixed":"2020-05-29"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://blog.google/documents/70/Exposure_Notification_-_Bluetooth_Specification_v1.2.2.pdf"},{"type":"FIX","url":"https://github.com/google/exposure-notifications-internals/commit/8f751a666697"},{"type":"FIX","url":"https://github.com/google/exposure-notifications-internals/commit/8f751a666697c3cae0a56ae3464c2c6cbe31b69e"},{"type":"EVIDENCE","url":"https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200611.pdf"},{"type":"EVIDENCE","url":"https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200616-2.pdf"},{"type":"EVIDENCE","url":"https://github.com/normanluhrmann/infosec/raw/master/exposure-notification-vulnerability-20200616.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/google/exposure-notifications-internals","events":[{"introduced":"0"},{"fixed":"8f751a666697"},{"fixed":"8f751a666697c3cae0a56ae3464c2c6cbe31b69e"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13702.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}