Vulnerability: Premature Expiration of Verification Codes in Exposure Notification Server

Vulnerability: Premature Expiration of Verification Codes in Exposure Notification Server

CVE-2021-22565 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.

Learn more about our Cis Benchmark Audit For Server Software.