peter bassill · operator
$ cve CVE-2020-5723 JSON

CVE-2020-5723

9.8
CRITICAL · CVSS 3.1 · EPSS 5.9% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.89% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-312
On CISA KEVno
Public exploitnone known
Published2020-03-30
Last modified2026-06-17

Affected (6)

VendorProduct
grandstreamucm6202
grandstreamucm6202 firmware
grandstreamucm6204
grandstreamucm6204 firmware
grandstreamucm6208
grandstreamucm6208 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD