CVE-2020-5723 is a critical vulnerability affecting Grandstream UCM6200 series IP PBX devices running firmware version 1.0.20.22 and below. It involves the storage of unencrypted user passwords in an SQLite database, allowing an unauthenticated attacker to remotely retrieve all stored credentials. With a CVSS score of 9.8 (Critical), this flaw presents a significant risk, as it can lead to complete compromise of the system and potentially elevated privileges. While not currently on the KEV catalog, a Metasploit module exists for credential dumping, indicating readily available exploit code, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.20.22CPE matchmatch criteria | cpe:2.3:o:grandstream:ucm6202_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.20.22CPE matchmatch criteria | cpe:2.3:o:grandstream:ucm6204_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.20.22CPE matchmatch criteria | cpe:2.3:o:grandstream:ucm6208_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020Grandstream UCM62xx Multiple SQL Injections
Mar 30, 2020