9

CVE-2020-5763

Exploit
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Grandstream ≫ Ht801 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht801 Version -
Grandstream ≫ Ht802 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht802 Version -
Grandstream ≫ Ht812 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht812 Version -
Grandstream ≫ Ht814 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht814 Version -
Grandstream ≫ Ht818 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht818 Version -
Grandstream ≫ Ht813 Firmware Version <= 1.0.17.5
   Grandstream ≫ Ht813 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.73% 0.841
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

CWE-489 Active Debug Code

The product is released with debugging code still enabled or active.

https://www.tenable.com/security/research/tra-2020-43
Third Party Advisory
Exploit
https://www.tenable.com/security/research/tra-2020-47
Third Party Advisory
VDB Entry