Junglewise Threat Intelligence

CVE-2020-5847: Unraid Remote Code Execution Vulnerability

CVE-2020-5847 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Unraid. Vendors: Unraid.

Executive brief

Unraid versions through 6.8.0 contain a remote code execution vulnerability due to the insecure use of the extract() PHP function. An unauthenticated attacker can exploit this to execute code as root, often by chaining it with CVE-2020-5849 for initial access.

Affected products

  • Unraid Unraid up to and including 6.8.0

Timeline

  • 2020-02-06: disclosed: Initial disclosure by Sysdream
  • 2020-03-16: advisory: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry date

Related threats