CVE-2020-36473 describes a low-severity vulnerability in UCWeb UC Browser versions 12.12.3.1219 through 12.12.3.1226, where the application uses cleartext HTTP for communication. This insecure transmission allows a man-in-the-middle attacker to passively intercept and discover visited URLs. The CVSS score is 3.7 (LOW), indicating a network attack vector with high attack complexity, requiring no user interaction, and resulting in a low impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.12.3.1219, <= 12.12.3.1226CPE matchmatch criteria | cpe:2.3:a:ucweb:ucweb_uc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.