CVE-2020-17153 is a spoofing vulnerability affecting Microsoft Edge for Android. This medium-severity vulnerability, with a CVSS score of 6.1, could allow an unauthenticated attacker to trick a user through a network-based attack requiring user interaction, potentially leading to limited impact on confidentiality and integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received minimal community discussion and media coverage, it was addressed in Microsoft's December 2020 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.