Skip to content
COOEY

EXPOSURES › CVE-2020-5849

CVE-2020-5849

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-5849 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatchedauth-bypass

Unraid's authentication bypass vulnerability allowed attackers to access the administrative interface, which can be chained with another CVE for remote code execution.

Unraid's authentication bypass vulnerability (CVE-2020-5849) allowed attackers to gain access to the administrative interface, and when chained with CVE-2020-5847, it enabled remote code execution. DIB organizations should care because this exposes administrative functions and can lead to full system compromise, impacting compliance with security requirements. Organizations should ensure all software is patched and monitor for chainable vulnerabilities.

Shame score — The vulnerability was actively exploited (KEV) and chainable with another CVE for remote code execution, indicating a significant security failure in authentication and input validation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unraid's authentication bypass vulnerability was widely recognized as a critical flaw, especially given its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploit
cooey ↗ severe-fallout -0.80
NVD entry confirms the vulnerability allows attackers to bypass authentication and gain access to the administrative interface, chainable with another CVE for remote code execution, indicating severe
"Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution."
CISA ↗ severe-fallout -0.50
CISA's inclusion of the vulnerability in the KEV catalog signals active exploitation, reflecting severe fallout for Unraid and its users.
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
app.opencve.io ↗ severe-fallout -0.50
CVEFeed's emphasis on KEV as a high-signal input for risk-based patch management underscores the severity of the vulnerability's exploitation.
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch mana"
www.cvefind.com ↗ severe-fallout +0.00
CVEFind provides neutral, factual data about the vulnerability without commentary on Unraid's handling.
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
NIST ↗ severe-fallout +0.00
NIST's NVD entry is neutral, providing a factual record of the vulnerability without sentiment.
NVD ↗ severe-fallout +0.00
OpenCVE provides neutral, factual data about CVEs without commentary on Unraid's handling.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.