9.8
CVE-2020-6871
- EPSS 0.4%
- Published 20.07.2020 18:15:12
- Last modified 21.11.2024 05:36:19
- Source psirt@zte.com.cn
- Teams watchlist Login
- Open Login
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>
Data is provided by the National Vulnerability Database (NVD)
Zte ≫ R8500g4 Firmware Version03.05.0020
Zte ≫ R8500g4 Firmware Version03.05.0400
Zte ≫ R8500g4 Firmware Version03.06.0100
Zte ≫ R8500g4 Firmware Version03.07.0101
Zte ≫ R8500g4 Firmware Version03.07.0103
Zte ≫ R5500g4 Firmware Version03.06.0100
Zte ≫ R5500g4 Firmware Version03.07.0100
Zte ≫ R5500g4 Firmware Version03.07.0200
Zte ≫ R5500g4 Firmware Version03.08.0100
Zte ≫ R5300g4 Firmware Version03.04.0020
Zte ≫ R5300g4 Firmware Version03.05.0040
Zte ≫ R5300g4 Firmware Version03.05.0043
Zte ≫ R5300g4 Firmware Version03.05.0044
Zte ≫ R5300g4 Firmware Version03.05.0045
Zte ≫ R5300g4 Firmware Version03.05.0046
Zte ≫ R5300g4 Firmware Version03.05.0047
Zte ≫ R5300g4 Firmware Version03.07.0100
Zte ≫ R5300g4 Firmware Version03.07.0108
Zte ≫ R5300g4 Firmware Version03.07.0200
Zte ≫ R5300g4 Firmware Version03.07.0300
Zte ≫ R5300g4 Firmware Version03.08.0100
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.4% | 0.579 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.