PT-2020-18646 · Grandstream · Grandstream Ucm6200 Series

Published

2020-03-30

·

Updated

2020-04-01

·

CVE-2020-5723

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grandstream UCM6200 series versions 1.0.20.22 and below
Description The issue allows an attacker to retrieve all passwords and possibly gain elevated privileges due to the storage of unencrypted user passwords in an SQLite database.
Recommendations For Grandstream UCM6200 series versions 1.0.20.22 and below, update to a version above 1.0.20.22 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5723

Affected Products

Grandstream Ucm6200 Series