« Volver al listado

CVE-2024-0840

Estado: AplazadaAlta (8.8)—

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0840",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0840",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-01T19:17:53.854809Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "vendor": "Grandstream",
          "product": "UCM Series",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "<1.0.20.52",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:grandstream:ucm6202_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "grandstream",
          "product": "ucm6202_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.20.52",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:grandstream:ucm6204_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "grandstream",
          "product": "ucm6204_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.20.52",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:grandstream:ucm6208_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "grandstream",
          "product": "ucm6208_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.20.52",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:grandstream:ucm6510_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "grandstream",
          "product": "ucm6510_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.0.20.52",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-29T19:15:19.730",
  "references": [
    {
      "url": "https://vulncheck.com/advisories/grand-stream-param-injection",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://vulncheck.com/advisories/grand-stream-param-injection",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-141"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.\n"
    },
    {
      "lang": "es",
      "value": "La central IP Grandstream UCM Series anterior a la versión de firmware 1.0.20.52 se ve afectada por una vulnerabilidad de inyección de parámetros en la interfaz HTTP. Un atacante remoto y autenticado puede ejecutar código arbitrario enviando una solicitud HTTP manipulada. La autenticación puede ser posible utilizando un usuario y una contraseña predeterminados. Los modelos afectados son UCM6202, UCM6204, UCM6208 y UCM6510."
    }
  ],
  "lastModified": "2026-06-17T06:54:24.887",
  "sourceIdentifier": "disclosure@vulncheck.com"
}