SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6870

The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability.

HIGH 8.0EPSS 0.62%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, modify, upload, or delete files, causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115

CVSS 3.1
8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Affected
zte/netnumen u31 r10 firmware
Source
psirt@zte.com.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.