I learned that <eq> does not match portrevision, so <ge> works better. And CVE-2020-13956 only mentions 3.1 and later and not earlier CPE versions.