Known Vulnerabilities for Ucm6204 Firmware by Grandstream
Listed below are 9 of the newest known vulnerabilities associated with "Ucm6204 Firmware" by "Grandstream".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5759 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticat... | 9.8 - CRITICAL | 2020-07-17 | 2020-07-23 |
| CVE-2020-5758 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authentica... | 8.8 - HIGH | 2020-07-17 | 2020-07-23 |
| CVE-2020-5757 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authentica... | 9.8 - CRITICAL | 2020-07-17 | 2020-07-23 |
| CVE-2020-5726 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote u... | 7.5 - HIGH | 2020-03-30 | 2020-03-31 |
| CVE-2020-5725 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. ... | 5.9 - MEDIUM | 2020-03-30 | 2020-03-31 |
| CVE-2020-5724 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. ... | 7.5 - HIGH | 2020-03-30 | 2020-03-30 |
| CVE-2020-5723 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker ... | 9.8 - CRITICAL | 2020-03-30 | 2020-04-01 |
| CVE-2019-10663 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord p... | 8.8 - HIGH | 2019-03-30 | 2019-04-01 |
| CVE-2019-10662 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharact... | 8.8 - HIGH | 2019-03-30 | 2023-03-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Grandstream | Ucm6204 Firmware | 1.0.20.23 | |||
| Operating System | Grandstream | Ucm6204 Firmware | 1.0.20.22 |