PatchSiren cyber security CVE debrief
CVE-2020-5722 Grandstream CVE debrief
CVE-2020-5722 is a SQL injection vulnerability affecting Grandstream UCM6200 series devices. In the supplied public records, CISA added the issue to its Known Exploited Vulnerabilities catalog on 2022-01-28 and set a remediation due date of 2022-07-28, indicating this is a vulnerability that should be treated as urgently actionable. The supplied corpus does not include a CVSS score, so prioritization here is driven by KEV inclusion and the vendor/product scope rather than a provided numeric severity.
- Vendor
- Grandstream
- Product
- UCM6200
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-01-28
- Original CVE updated
- 2022-01-28
- Advisory published
- 2022-01-28
- Advisory updated
- 2022-01-28
Who should care
Organizations that operate Grandstream UCM6200 series systems should care first, especially teams responsible for patching, internet-facing management exposure, and asset inventory for communications or appliance-based infrastructure. Security operations teams should also track it because CISA classified it as a known exploited vulnerability.
Technical summary
The available sources identify the flaw as a SQL injection issue in the Grandstream UCM6200 series. SQL injection can allow maliciously crafted input to alter backend database queries if inputs are not properly validated and parameterized. No further exploitation details, impact scope, or affected component breakdown are provided in the supplied corpus.
Defensive priority
High. CISA placed CVE-2020-5722 in the Known Exploited Vulnerabilities catalog, which is a strong indicator that it should be remediated promptly. Use the vendor’s update guidance and verify exposed assets are covered.
Recommended defensive actions
- Apply updates per vendor instructions as directed by CISA.
- Inventory all Grandstream UCM6200 series devices to confirm exposure and patch status.
- Prioritize internet-facing or remotely reachable deployments for immediate review.
- Validate that administrative or management interfaces are not unnecessarily exposed.
- Track remediation against CISA’s KEV due date and confirm closure in asset management records.
Evidence notes
CISA KEV metadata in the supplied source item names the vendorProject as Grandstream, the product as UCM6200, the vulnerabilityName as 'Grandstream Networks UCM6200 Series SQL Injection Vulnerability,' dateAdded as 2022-01-28, dueDate as 2022-07-28, and requiredAction as 'Apply updates per vendor instructions.' The provided CVE/NVD references establish the CVE identifier and product naming, but the supplied corpus does not include a CVSS score.
Sources and references
Verified primary and authoritative sources
-
CVE-2020-5722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2020-5722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2020-5722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-5722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.