CVE-2020-1902
Estado: ModificadaAlta (7.5)—
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-1902",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-assign@fb.com",
"affectedData": [
{
"vendor": "Facebook",
"product": "WhatsApp for Android",
"versions": [
{
"status": "affected",
"version": "2.20.140"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.20.140",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "unspecified",
"lessThan": "2.20.108",
"versionType": "custom"
}
]
},
{
"vendor": "Facebook",
"product": "WhatsApp Business for Android",
"versions": [
{
"status": "affected",
"version": "2.20.49"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.20.49",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "unspecified",
"lessThan": "2.20.35",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-10-06T18:15:15.627",
"references": [
{
"url": "https://www.whatsapp.com/security/advisories/2020/",
"tags": [
"Vendor Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://www.whatsapp.com/security/advisories/2020/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-assign@fb.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP."
},
{
"lang": "es",
"value": "Un usuario que realiza una búsqueda rápida en un mensaje altamente reenviado en WhatsApp para Android desde versiones v2.20.108 hasta v2.20.140 o WhatsApp Business para Android desde versiones v2.20.35 hasta v2.20.49, podría haber sido enviado al servicio de Google por medio de un HTTP plano"
}
],
"lastModified": "2026-06-17T03:02:35.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "CA96B32C-5673-4B36-AE2C-D318744B0E25",
"versionEndIncluding": "2.20.140",
"versionStartIncluding": "2.20.108"
},
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "D098DF3C-6EA3-470E-865C-601827ABFB35",
"versionEndIncluding": "2.20.49",
"versionStartIncluding": "2.20.35"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-assign@fb.com"
}