CVE-2020-6870 Information
Feb 14, 2021
cve
Description
The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password and illegally download modify upload or delete files causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013043
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.0
Share on: