HIGH · 7.1

CVE-2022-39071

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers wi...

Vulnerability Description

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteBlade A52 Firmware< m02
ZteBlade A52-
ZteBlade A51 Firmware< m07
ZteBlade A51-
ZteBlade A3 Lite Firmware< m09
ZteBlade A3 Lite-
ZteBlade A5 2020 Firmware< m05
ZteBlade A5 2020-
ZteBlade L210 Firmware< 1.14
ZteBlade L210-
ZteBlade A7S Firmware< 2.2
ZteBlade A7S-
ZteBlade A31 Firmware< m03
ZteBlade A31-
ZteBlade A31 Plus Firmware< m04
ZteBlade A31 Plus-
ZteBlade A5 2019 Firmware< m13
ZteBlade A5 2019-
ZteBlade A71 Firmware< 2.4
ZteBlade A71-

References

FAQ

What is CVE-2022-39071?

CVE-2022-39071 is a vulnerability with a CVSS score of 7.1 (HIGH). There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers wi...

How severe is CVE-2022-39071?

CVE-2022-39071 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-39071?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Blade A52 Firmware, Zte Blade A52, Zte Blade A51 Firmware, Zte Blade A51, Zte Blade A3 Lite Firmware.