Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6779

Опубликовано: 26 янв. 2021
Источник: nvd
CVSS3: 10
CVSS2: 10
EPSS Низкий

Описание

Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as well as a high availability impact on the database itself. In addition, an attacker may execute arbitrary commands on the underlying operating system.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:bosch:fsm-2500_firmware:*:*:*:*:*:*:*:*
Версия до 5.2 (включая)
cpe:2.3:h:bosch:fsm-2500:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:bosch:fsm-5000_firmware:*:*:*:*:*:*:*:*
Версия до 5.2 (включая)
cpe:2.3:h:bosch:fsm-5000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.09936
Низкий

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-798
CWE-798

Связанные уязвимости

github
больше 3 лет назад

Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as well as a high availability impact on the database itself. In addition, an attacker may execute arbitrary commands on the underlying operating system.

EPSS

Процентиль: 93%
0.09936
Низкий

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-798
CWE-798