CVE-2021-22565
Estado: ModificadaMedia (6.5)—
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
- NVD-CWE-Other
Referencias
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2
- https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2
- https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-22565",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-coordination@google.com",
"affectedData": [
{
"vendor": "Google LLC",
"product": "Google Exposure-notifications-verification-server",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-12-09T13:15:08.767",
"references": [
{
"url": "https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v",
"tags": [
"Third Party Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater."
},
{
"lang": "es",
"value": "Un atacante podría hacer expirar prematuramente un código de verificación, haciéndolo inusable por el paciente, haciendo que éste no pueda cargar sus TEKs para generar notificaciones de exposición. Se recomienda actualizar el Servidor de Notificaciones de Exposición a la versión 1.1.2 o superior"
}
],
"lastModified": "2026-06-17T03:37:26.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:exposure_notification_verification_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C922D69E-FD60-4DD6-9E8F-96F5FB422462",
"versionEndExcluding": "1.1.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-coordination@google.com"
}