7.1

CVE-2022-39071

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.

Data is provided by the National Vulnerability Database (NVD)
ZteBlade A52 Firmware Version < m02
   ZteBlade A52 Version-
ZteBlade A51 Firmware Version < m07
   ZteBlade A51 Version-
ZteBlade A3 Lite Firmware Version < m09
   ZteBlade A3 Lite Version-
ZteBlade A5 2020 Firmware Version < m05
   ZteBlade A5 2020 Version-
ZteBlade L210 Firmware Version < 1.14
   ZteBlade L210 Version-
ZteBlade A7s Firmware Version < 2.2
   ZteBlade A7s Version-
ZteBlade A31 Firmware Version < m03
   ZteBlade A31 Version-
ZteBlade A31 Plus Firmware Version < m04
   ZteBlade A31 Plus Version-
ZteBlade A5 2019 Firmware Version < m13
   ZteBlade A5 2019 Version-
ZteBlade A71 Firmware Version < 2.4
   ZteBlade A71 Version-
ZteBlade A72 Firmware Version < 11.0.3
   ZteBlade A72 Version-
ZteBlade V20 Smart Firmware Version < 1.14
   ZteBlade V20 Smart Version-
ZteBlade V30 Firmware Version < 1.11
   ZteBlade V30 Version-
ZteBlade V30 Vita Firmware Version < 1.11
   ZteBlade V30 Vita Version-
ZteV40 Pro Firmware Version < 11.0.4_9046
   ZteV40 Pro Version-
ZteBlade V40 Vita Firmware Version < 11.0.2_8045
   ZteBlade V40 Vita Version-
ZteAxon 40 Ultra Firmware Version < 1.0.0b26
   ZteAxon 40 Ultra Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.096
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H