Lucene search

K
cvelistTenableCVELIST:CVE-2020-5758
HistoryJul 17, 2020 - 8:35 p.m.

CVE-2020-5758

2020-07-1720:35:47
CWE-78
tenable
www.cve.org
3

AI Score

9

Confidence

High

EPSS

0.001

Percentile

42.9%

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM’s “Old” HTTPS API.

CNA Affected

[
  {
    "product": "Grandstream UCM6200 Series",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions 1.0.20.23 and below"
      }
    ]
  }
]

AI Score

9

Confidence

High

EPSS

0.001

Percentile

42.9%

Related for CVELIST:CVE-2020-5758