CVE-2022-39071

There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:blade_a52_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a52:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zte:blade_a51_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a51:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zte:blade_a3_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a3_lite:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:zte:blade_a5_2020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a5_2020:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:zte:blade_l210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_l210:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:zte:blade_a7s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a7s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:zte:blade_a31_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a31:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:zte:blade_a31_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a31_plus:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:zte:blade_a5_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a5_2019:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:zte:blade_a71_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a71:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:zte:blade_a72_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a72:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:zte:blade_v20_smart_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v20_smart:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:zte:blade_v30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v30:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:zte:blade_v30_vita_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v30_vita:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:zte:v40_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:v40_pro:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:zte:blade_v40_vita_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v40_vita:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:zte:axon_40_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_ultra:-:*:*:*:*:*:*:*

History

07 Jun 2023, 14:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE NVD-CWE-Other
References (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1030664 - (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1030664 - Vendor Advisory
CPE cpe:2.3:h:zte:blade_a31:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a5_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a72:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_v20_smart_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a31_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a7s:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a5_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_v30_vita_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a52:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a71:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_l210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a72_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:v40_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a3_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:axon_40_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:v40_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a31_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_v30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_v40_vita_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v40_vita:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v30:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a5_2020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v20_smart:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a7s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a3_lite:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a5_2020:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a51_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a51:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_a31_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a52_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_l210:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:blade_v30_vita:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:blade_a71_firmware:*:*:*:*:*:*:*:*

30 May 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-30 23:15

Updated : 2024-02-04 23:37


NVD link : CVE-2022-39071

Mitre link : CVE-2022-39071

CVE.ORG link : CVE-2022-39071


JSON object : View

Products Affected

zte

  • blade_a51
  • blade_a31_firmware
  • axon_40_ultra
  • blade_v30_vita
  • blade_a3_lite
  • blade_a31_plus_firmware
  • blade_v30_vita_firmware
  • blade_l210
  • blade_v40_vita_firmware
  • blade_a5_2020_firmware
  • blade_a3_lite_firmware
  • blade_a72_firmware
  • axon_40_ultra_firmware
  • v40_pro
  • blade_v40_vita
  • blade_a52
  • blade_a5_2020
  • v40_pro_firmware
  • blade_a31
  • blade_a71_firmware
  • blade_a7s_firmware
  • blade_a5_2019_firmware
  • blade_a71
  • blade_v20_smart
  • blade_a51_firmware
  • blade_a5_2019
  • blade_v30
  • blade_v30_firmware
  • blade_a52_firmware
  • blade_a31_plus
  • blade_a72
  • blade_a7s
  • blade_l210_firmware
  • blade_v20_smart_firmware