← Back

CVE-2020-5723

nvd nist
Published: Mar 30, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

Affected (3)

3 products
Ucm6202 Firmware
Ucm6204 Firmware
Ucm6208 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.20.22
Running on/withPlatform Versions
Grandstream
Ucm6202
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.20.22
Running on/withPlatform Versions
Grandstream
Ucm6204
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.20.22
Running on/withPlatform Versions
Grandstream
Ucm6208
All versions

References (2)

Source: vulnreport@tenable.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.