9

CVE-2020-5763

Exploit
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrandstreamHt801 Firmware Version <= 1.0.17.5
   GrandstreamHt801 Version-
GrandstreamHt802 Firmware Version <= 1.0.17.5
   GrandstreamHt802 Version-
GrandstreamHt812 Firmware Version <= 1.0.17.5
   GrandstreamHt812 Version-
GrandstreamHt814 Firmware Version <= 1.0.17.5
   GrandstreamHt814 Version-
GrandstreamHt818 Firmware Version <= 1.0.17.5
   GrandstreamHt818 Version-
GrandstreamHt813 Firmware Version <= 1.0.17.5
   GrandstreamHt813 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.793
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

CWE-489 Active Debug Code

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.