Skip to content
COOEY

EXPOSURES › CVE-2020-8816

CVE-2020-8816

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8816 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Pi-hole AdminLTE allowed remote code execution via a crafted DHCP static lease to privileged dashboard users.

A remote code execution vulnerability in Pi-hole AdminLTE (CVE-2020-8816) allowed attackers to execute arbitrary code on systems running Pi-hole Web v4.3.2 by exploiting a crafted DHCP static lease. DIB organizations should care because this flaw was actively exploited in the wild (KEV), enabling attackers to compromise network security monitoring and potentially pivot to other systems. Organizations must ensure they are running patched versions of Pi-hole and restrict access to privileged dashboard users to mitigate this risk.

Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution to privileged users, indicating a significant security oversight that could have been mitigated with proper patching and access controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.