The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGrandstream Ucm6202
HWGrandstreamall versionsGrandstream Ucm6202 Firmware
OSGrandstream< 1.0.20.22Grandstream Ucm6204
HWGrandstreamall versionsGrandstream Ucm6204 Firmware
OSGrandstream< 1.0.20.22Grandstream Ucm6208
HWGrandstreamall versionsGrandstream Ucm6208 Firmware
OSGrandstream< 1.0.20.22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-5757CRITICAL9.8PL ✓same product
Command injection w Grandstream UCM6200 — wykonanie kodu jako root
CVE-2020-5759CRITICAL9.8PL ✓same product
Command Injection w Grandstream UCM6200 via SSH — wykonanie poleceń jako root
CVE-2020-5758HIGH8.8same product
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP...
CVE-2020-5726HIGH7.5same product
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8...
CVE-2020-5724HIGH7.5same product
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websoc...