Security Advisory

CVE-2020-6780

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-01-25 18:41:41
Last updated 2024-09-17 01:11:14
Assigner bosch
State PUBLISHED

Description

Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.