VulnerabilityModified
CVE-2020-12474
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
MEDIUM 6.5EPSS 2.53%
Does this matter?
Lower severity and a low EPSS score (2.53%). Track it; it rarely justifies an emergency change on its own.
Description
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 2.53% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- telegram/telegram · telegram/telegram desktop
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.