Skip to content
COOEY

EXPOSURES › CVE-2020-11651

CVE-2020-11651

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11651 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrcesupply-chain

SaltStack Salt's improperly validated ClearFuncs method calls allowed unauthenticated remote access to tokens and command execution on minions.

An authentication bypass in SaltStack Salt's salt-master process let attackers retrieve user tokens and run commands on minions without authentication. DIB orgs must patch this unpatched, KEV-listed flaw immediately to prevent remote code execution and supply-chain compromise. The vendor's failure to validate method calls represents a negligent, avoidable security lapse.

Shame score — A known, unpatched authentication bypass enabling remote command execution on critical infrastructure software, listed in CISA's KEV catalog, reflects negligent validation logic and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.20
Vulnerability disclosed; no direct press coverage or authority condemnation found in provided sources.
cooey ↗ neutral -0.20
Neutral disclosure; notes best practices mitigate risk.
"Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
CISA ↗ neutral +0.00
No relevant content; generic CISA page.
www.dell.com ↗ neutral +0.00
No relevant content; Dell support page.
www.cvefind.com ↗ neutral +0.00
No relevant content; CVE database site.
www.arista.com ↗ neutral +0.00
No relevant content; Arista advisories page.
No relevant content; Local news article.
www.strix.ai ↗ neutral +0.00
No relevant content; CVE database site.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.