EXPOSURES › CVE-2020-16846
CVE-2020-16846
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection.
SaltStack Salt allowed unauthenticated users to inject shell commands through its API, enabling remote code execution on affected systems. DIB organizations must ensure their Salt deployments are patched and monitored, as this flaw was actively exploited in the wild and could compromise infrastructure management systems. Organizations should verify their Salt versions and apply the latest security updates immediately to prevent unauthorized access.
Shame score — A critical shell injection flaw allowing unauthenticated remote code execution was actively exploited in the wild, indicating severe negligence in patch management and security monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client."