CVE-2020-5723
30.03.2020, 20:15
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.Enginsight
Vendor | Product | Version |
---|---|---|
grandstream | ucm6202_firmware | 𝑥 < 1.0.20.22 |
grandstream | ucm6204_firmware | 𝑥 < 1.0.20.22 |
grandstream | ucm6208_firmware | 𝑥 < 1.0.20.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration