Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-6780

17
FAUCET Score

CVE-2020-6780 describes a vulnerability in Bosch FSM-2500 and FSM-5000 servers (up to version 5.2) where user password hashes are stored using insufficient computational effort (MD5). An authenticated remote attacker with administrative privileges can exploit this to dump other user credentials and potentially recover plaintext passwords through brute-forcing. With a CVSS score of 4.9 (Medium), this vulnerability requires high privileges for exploitation but can lead to a complete compromise of confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.2CPE matchmatch criteria
cpe:2.3:o:bosch:fsm-2500_firmware:*:*:*:*:*:*:*:*
<= 5.2CPE matchmatch criteria
cpe:2.3:o:bosch:fsm-5000_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.7
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 42nd percentile among its peer group of 3,565 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted

Vendor Advisories (6)

capnprotollm-capnproto-7c65b89b18eec4a6CRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021
openwrtllm-openwrt-37f2ba0f600c7a88CRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021
gcpllm-gcp-ef2c75da53e561a2CRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021
kongllm-kong-265f0ffa6fc9806dCRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021
hanwhallm-hanwha-d85ce829f835de84CRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021
proxmoxllm-proxmox-9c54b19288ae5681CRITICAL

Two Vulnerabilities in Bosch Fire Monitoring System (FSM)

Jan 20, 2021

References

psirt.bosch.com / security-advisories/BOSCH-SA-332072-BT.html
Vendor Advisory