Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HGrandstream Ucm6202
HWGrandstreamwszystkie wersjeGrandstream Ucm6202 Firmware
OSGrandstream≤ 1.0.20.23Grandstream Ucm6204
HWGrandstreamwszystkie wersjeGrandstream Ucm6204 Firmware
OSGrandstream≤ 1.0.20.23Grandstream Ucm6208
HWGrandstreamwszystkie wersjeGrandstream Ucm6208 Firmware
OSGrandstream≤ 1.0.20.23
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
Powiązane podatności
CVE-2020-5757CRITICAL9.8PL ✓ten sam produkt
Command injection w Grandstream UCM6200 — wykonanie kodu jako root
CVE-2020-5759CRITICAL9.8PL ✓ten sam produkt
Command Injection w Grandstream UCM6200 via SSH — wykonanie poleceń jako root
CVE-2020-5723CRITICAL9.8PL ✓ten sam produkt
Grandstream UCM6200 — niezaszyfrowane hasła użytkowników w bazie SQLite
CVE-2020-5726HIGH7.5ten sam produkt
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8...
CVE-2020-5724HIGH7.5ten sam produkt
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websoc...