Known Vulnerabilities for Ucm6204 Firmware by Grandstream
Listed below are 9 of the newest known vulnerabilities associated with "Ucm6204 Firmware" by "Grandstream".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5759 json | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticat... | 9.8 - CRITICAL | 2020-07-17 | 2020-07-23 |
| CVE-2020-5758 json | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authentica... | 8.8 - HIGH | 2020-07-17 | 2020-07-23 |
| CVE-2020-5757 json | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authentica... | 9.8 - CRITICAL | 2020-07-17 | 2020-07-23 |
| CVE-2020-5726 json | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote u... | 7.5 - HIGH | 2020-03-30 | 2020-03-31 |
| CVE-2020-5725 json | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. ... | 5.9 - MEDIUM | 2020-03-30 | 2020-03-31 |
| CVE-2020-5724 json | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. ... | 7.5 - HIGH | 2020-03-30 | 2020-03-30 |
| CVE-2020-5723 json | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker ... | 9.8 - CRITICAL | 2020-03-30 | 2020-04-01 |
| CVE-2019-10663 json | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord p... | 8.8 - HIGH | 2019-03-30 | 2019-04-01 |
| CVE-2019-10662 json | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharact... | 8.8 - HIGH | 2019-03-30 | 2023-03-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Grandstream | Ucm6204 Firmware | 1.0.20.23 | |||
| Operating System | Grandstream | Ucm6204 Firmware | 1.0.20.22 |