Skip to content
COOEY

EXPOSURES › CVE-2020-5847

CVE-2020-5847

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-5847 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Unraid's insecure use of the extract PHP function allows remote code execution as root, enabling attackers to compromise storage servers.

Unraid's administrative interface is vulnerable to remote code execution due to improper input validation, allowing attackers to execute arbitrary commands as root. This failure is critical for DIB organizations relying on Unraid for secure data storage, as it directly violates CMMC/NIST 800-171 requirements for system integrity and access control. Organizations must immediately patch or replace Unraid deployments to prevent unauthorized access and data exfiltration.

Shame score — A high-severity RCE vulnerability in a widely used storage server OS that was actively exploited in the wild, indicating negligent input validation and a failure to patch known critical flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unraid's insecure use of PHP extract function allowed remote root code execution, a critical flaw with severe implications for users relying on its security.
cooey ↗ severe-fallout -0.60
The NVD entry highlights a critical remote code execution vulnerability in Unraid, indicating a severe security failure.
"Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.