CVE-2020-5723: SQL Injection
Published Mar 30, 2020
·Updated
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
Affected Software
12 affected components
Grandstream Ucm6202 Firmware<1.0.20.22
Grandstream Ucm6202
Grandstream Ucm6204 Firmware<1.0.20.22
Grandstream UCM6204
Grandstream Ucm6208 Firmware<1.0.20.22
Grandstream Ucm6208
All of the following
Grandstream Ucm6202 Firmware<1.0.20.22
Grandstream Ucm6202
All of the following
Grandstream Ucm6204 Firmware<1.0.20.22
Grandstream UCM6204
All of the following
Grandstream Ucm6208 Firmware<1.0.20.22
Grandstream Ucm6208
Event History
Mar 30, 2020
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-5723.
2
What is the severity of CVE-2020-5723?
The severity of CVE-2020-5723 is critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2020-5723?
The UCM6200 series versions 1.0.20.22 and below are affected by CVE-2020-5723.
4
How does CVE-2020-5723 impact user passwords?
CVE-2020-5723 allows an attacker to retrieve all passwords stored in an SQLite database.
5
Is it possible for an attacker to gain elevated privileges with CVE-2020-5723?
Yes, CVE-2020-5723 could allow an attacker to gain elevated privileges.