CVE-2020-5723
Estado: ModificadaCrítica (9.8)—
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.89%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-312
- CWE-312
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-5723",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Grandstream UCM6200 series",
"versions": [
{
"status": "affected",
"version": "1.0.20.20 and below"
}
]
}
]
}
],
"published": "2020-03-30T20:15:19.883",
"references": [
{
"url": "https://www.tenable.com/security/research/tra-2020-17",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/research/tra-2020-17",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnreport@tenable.com",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges."
},
{
"lang": "es",
"value": "La serie UCM6200 versiones 1.0.20.22 y por debajo, almacena contraseñas de usuario sin cifrar en una base de datos SQLite. Esto podría permitir a un atacante recuperar todas las contraseñas y posiblemente alcanzar privilegios elevados."
}
],
"lastModified": "2026-06-17T03:22:06.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:grandstream:ucm6202_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F55C1906-9C0D-4479-B545-059329485BCD",
"versionEndExcluding": "1.0.20.22"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:grandstream:ucm6202:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9864BD0F-BE9C-4F72-AB57-77036699029B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:grandstream:ucm6204_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D9A2414-684F-4C61-BCAC-E7967A7BFF2B",
"versionEndExcluding": "1.0.20.22"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:grandstream:ucm6204:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B5A26ABB-8BED-4E61-91AA-ABF1B90CBD81"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:grandstream:ucm6208_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3164240C-6CAB-4433-8EB3-5F09552A7F4D",
"versionEndExcluding": "1.0.20.22"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:grandstream:ucm6208:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EA744718-8862-4579-B9CF-E1E8137A02E6"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vulnreport@tenable.com"
}