ZeroHour

CVE-2020-5723

PoC
CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

Vendors
grandstream
Products
ucm6202 firmware, ucm6204 firmware, ucm6208 firmware
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.