SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-6877

A ZTE product is impacted by an information leak vulnerability.

HIGH 8.8EPSS 1.03%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the handheld terminal and access the device illegally for operation. This affects: ZXA10 eODN V2.3P2T1

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Affected
zte/zxa10 eodn firmware
Source
psirt@zte.com.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.