CVE-2021-22565
Status: ModifiedMedium (6.5)—
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.44%
- Percentile among all scored CVEs: 36
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
- NVD-CWE-Other
References
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2
- https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2
- https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v
Raw JSON (NVD)
Show
{
"id": "CVE-2021-22565",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-coordination@google.com",
"affectedData": [
{
"vendor": "Google LLC",
"product": "Google Exposure-notifications-verification-server",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-12-09T13:15:08.767",
"references": [
{
"url": "https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v",
"tags": [
"Third Party Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater."
},
{
"lang": "es",
"value": "Un atacante podría hacer expirar prematuramente un código de verificación, haciéndolo inusable por el paciente, haciendo que éste no pueda cargar sus TEKs para generar notificaciones de exposición. Se recomienda actualizar el Servidor de Notificaciones de Exposición a la versión 1.1.2 o superior"
}
],
"lastModified": "2026-06-17T03:37:26.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:exposure_notification_verification_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C922D69E-FD60-4DD6-9E8F-96F5FB422462",
"versionEndExcluding": "1.1.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-coordination@google.com"
}