EXPOSURES › CVE-2020-5847
CVE-2020-5847
HIGH ⌖ ON CISA KEV · EXPLOITEDUnraid's insecure use of the extract PHP function allows remote code execution as root, enabling attackers to compromise storage servers.
Unraid's administrative interface is vulnerable to remote code execution due to improper input validation, allowing attackers to execute arbitrary commands as root. This failure is critical for DIB organizations relying on Unraid for secure data storage, as it directly violates CMMC/NIST 800-171 requirements for system integrity and access control. Organizations must immediately patch or replace Unraid deployments to prevent unauthorized access and data exfiltration.
Shame score — A high-severity RCE vulnerability in a widely used storage server OS that was actively exploited in the wild, indicating negligent input validation and a failure to patch known critical flaws.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
"Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root."