HIGH · 8.0

CVE-2020-6870

The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and il...

Vulnerability Description

The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, modify, upload, or delete files, causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteNetnumen U31 R10 Firmwarev12.17.20t115
ZteNetnumen U31 R10-

References

FAQ

What is CVE-2020-6870?

CVE-2020-6870 is a vulnerability with a CVSS score of 8.0 (HIGH). The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and il...

How severe is CVE-2020-6870?

CVE-2020-6870 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-6870?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Netnumen U31 R10 Firmware, Zte Netnumen U31 R10.