Executive brief
Unraid 6.8.0 contains an authentication bypass vulnerability due to incorrect comparison logic. This flaw allows unauthenticated attackers to gain access to the administrative interface and can be chained with CVE-2020-5847 to achieve remote code execution as root.
Affected products
- Unraid Unraid 6.8.0
Timeline
- 2020-02-06: disclosed: Initial disclosure by Sysdream labs
- 2020-03-16: other: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog