CVE-2020-5724

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
30/03/2020
Last modified:
30/03/2020

Description

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:grandstream:ucm6202_firmware:*:*:*:*:*:*:*:* 1.0.20.22 (excluding)
cpe:2.3:h:grandstream:ucm6202:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ucm6204_firmware:*:*:*:*:*:*:*:* 1.0.20.22 (excluding)
cpe:2.3:h:grandstream:ucm6204:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ucm6208_firmware:*:*:*:*:*:*:*:* 1.0.20.22 (excluding)
cpe:2.3:h:grandstream:ucm6208:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools