First published: Mon Mar 30 2020(Updated: )
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Ucm6202 Firmware | <1.0.20.22 | |
Grandstream Ucm6202 | ||
Grandstream Ucm6204 Firmware | <1.0.20.22 | |
Grandstream UCM6204 | ||
Grandstream Ucm6208 Firmware | <1.0.20.22 | |
Grandstream Ucm6208 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-5723.
The severity of CVE-2020-5723 is critical with a severity value of 9.8.
The UCM6200 series versions 1.0.20.22 and below are affected by CVE-2020-5723.
CVE-2020-5723 allows an attacker to retrieve all passwords stored in an SQLite database.
Yes, CVE-2020-5723 could allow an attacker to gain elevated privileges.