Vulnerability Intelligence Report
CVE-2020-5723
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:5.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-312 ↗Cleartext Password Storage (CWE-312)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| grandstream | ucm6202_firmware | all |
| grandstream | ucm6202 | all |
| grandstream | ucm6204_firmware | all |
| grandstream | ucm6204 | all |
| grandstream | ucm6208_firmware | all |
| grandstream | ucm6208 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
5.704%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Tenable Network Security, Inc. · Vendor · USA |
| Reserved | 2020-01-06T00:00:00 |
| Published | 2020-03-30T19:03:22 |
| Last Updated | 2024-08-04T08:39:25 |
Community Chatter & Buzz