← Back

CVE-2020-5759

nvd nist
Published: Jul 17, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.

Affected (3)

3 products
Ucm6202 Firmware
Ucm6204 Firmware
Ucm6208 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6202
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6204
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.20.23
Running on/withPlatform Versions
Grandstream
Ucm6208
All versions

References (3)

Source: vulnreport@tenable.com
Not Applicable
Source: nvd@nist.gov
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.