The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NGrandstream Ucm6202
HWGrandstreamwszystkie wersjeGrandstream Ucm6202 Firmware
OSGrandstream< 1.0.20.22Grandstream Ucm6204
HWGrandstreamwszystkie wersjeGrandstream Ucm6204 Firmware
OSGrandstream< 1.0.20.22Grandstream Ucm6208
HWGrandstreamwszystkie wersjeGrandstream Ucm6208 Firmware
OSGrandstream< 1.0.20.22
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLiAuth Bypass
Powiązane podatności
CVE-2020-5757CRITICAL9.8PL ✓ten sam produkt
Command injection w Grandstream UCM6200 — wykonanie kodu jako root
CVE-2020-5759CRITICAL9.8PL ✓ten sam produkt
Command Injection w Grandstream UCM6200 via SSH — wykonanie poleceń jako root
CVE-2020-5723CRITICAL9.8PL ✓ten sam produkt
Grandstream UCM6200 — niezaszyfrowane hasła użytkowników w bazie SQLite
CVE-2020-5758HIGH8.8ten sam produkt
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP...
CVE-2020-5726HIGH7.5ten sam produkt
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8...