Junglewise Threat Intelligence

CVE-2020-5849: Unraid Authentication Bypass Vulnerability

CVE-2020-5849 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Unraid. Vendors: Unraid.

Executive brief

Unraid 6.8.0 contains an authentication bypass vulnerability due to incorrect comparison logic. This flaw allows unauthenticated attackers to gain access to the administrative interface and can be chained with CVE-2020-5847 to achieve remote code execution as root.

Affected products

  • Unraid Unraid 6.8.0

Timeline

  • 2020-02-06: disclosed: Initial disclosure by Sysdream labs
  • 2020-03-16: other: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats