The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
https://www.tenable.com/security/research/tra-2020-17
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5723