← Back

CVE-2020-5758

nvd nist
Published: Jul 17, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.

Affected (3)

3 products
Ucm6202 Firmware
Ucm6204 Firmware
Ucm6208 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6202
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6204
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6208
All versions

References (3)

Source: vulnreport@tenable.com
Broken LinkThird Party Advisory
Source: nvd@nist.gov
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory

Timeline

No history available yet.