Skip to content
COOEY

EXPOSURES › CVE-2020-16846

CVE-2020-16846

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-16846 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

An unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection.

SaltStack Salt allowed unauthenticated users to inject shell commands through its API, enabling remote code execution on affected systems. DIB organizations must ensure their Salt deployments are patched and monitored, as this flaw was actively exploited in the wild and could compromise infrastructure management systems. Organizations should verify their Salt versions and apply the latest security updates immediately to prevent unauthorized access.

Shame score — A critical shell injection flaw allowing unauthenticated remote code execution was actively exploited in the wild, indicating severe negligence in patch management and security monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
cooey ↗ severe-fallout -0.60
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.