CVE-2020-6779

CRITICAL

Bosch FSM-2500 and FSM-5000 Firmware <= 5.2 - Unauthenticated Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as well as a high availability impact on the database itself. In addition, an attacker may execute arbitrary commands on the underlying operating system.

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.0370
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
bosch/fsm-2500_firmware < 5.2
bosch/fsm-5000_firmware < 5.2
Published Jan 26, 2021
Tracked Since Feb 18, 2026