CVE-2020-5723
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 5.9%
from disclosure to weapon0 days
Published on NVDMar 30
metasploitMar 30
exploitation probability
5.9%top 7% of all CVEs
observed exploitation
nono source reports it
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
Affected products
n/a · Grandstream UCM6200 series