Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6780

Опубликовано: 26 янв. 2021
Источник: nvd
CVSS3: 4.4
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:bosch:fsm-2500_firmware:*:*:*:*:*:*:*:*
Версия до 5.2 (включая)
cpe:2.3:h:bosch:fsm-2500:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:bosch:fsm-5000_firmware:*:*:*:*:*:*:*:*
Версия до 5.2 (включая)
cpe:2.3:h:bosch:fsm-5000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00097
Низкий

4.4 Medium

CVSS3

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-916
CWE-916

Связанные уязвимости

github
больше 3 лет назад

Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.

EPSS

Процентиль: 27%
0.00097
Низкий

4.4 Medium

CVSS3

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-916
CWE-916