CVE-2020-9202
Estado: ModificadaMedia (4.4)—
Se presenta una vulnerabilidad de divulgación de información en el software TE Mobile versiones V600R006C10, V600R006C10SPC100. Debido al almacenamiento inapropiado de alguna información en determinado escenario específico, el atacante puede obtener información en el dispositivo de la víctima para iniciar el ataque, una explotación con éxito podría causar una divulgación de información
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-922
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-9202",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "TE Mobile",
"versions": [
{
"status": "affected",
"version": "V600R006C10,V600R006C10SPC100"
}
]
}
]
}
],
"published": "2020-12-24T16:15:16.210",
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201209-01-informationleak-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201209-01-informationleak-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful exploit could cause information disclosure."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de divulgación de información en el software TE Mobile versiones V600R006C10, V600R006C10SPC100. Debido al almacenamiento inapropiado de alguna información en determinado escenario específico, el atacante puede obtener información en el dispositivo de la víctima para iniciar el ataque, una explotación con éxito podría causar una divulgación de información"
}
],
"lastModified": "2026-06-17T03:27:34.613",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:huawei:te_mobile:v600r006c10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B60906C-2978-493F-BBDF-10A071D12687"
},
{
"criteria": "cpe:2.3:a:huawei:te_mobile:v600r006c10spc100:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39D31988-4F1B-48AC-AC0F-B24C235ED9EA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@huawei.com"
}