ZeroHour

CVE-2020-11651

KEV PoC ×2large

Authentication Bypass and Unauthenticated RCE in SaltStack Salt

CISA: SaltStack Salt Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2020-11651 is a critical (CVSS 9.8) authentication bypass in SaltStack Salt's salt-master process: the ClearFuncs class fails to validate method calls, so a remote attacker can invoke privileged methods without authenticating. By sending crafted messages to the salt-master's network interface, an unauthenticated user can retrieve the master's root tokens/eauth credentials and use them to execute arbitrary commands on salt minions, yielding full remote code execution across the entire Salt deployment. Anyone running affected Salt versions before 2019.2.4 or 3000.x before 3000.2 — including Salt shipped in Debian, Ubuntu, openSUSE Leap, and VMware's Application Remote Collector — is exposed, especially masters reachable on their ZeroMQ ports. Exploitation is confirmed in the wild: the flaw is on CISA's KEV catalog, EPSS puts exploitation probability at 96.6%, attackers have been mass-scanning for vulnerable Salt installs, and breaches using this bug hit Cisco (six servers), LineageOS, Ghost, and DigiCert.

What to do: Upgrade salt-master to Salt 2019.2.4 or 3000.2 (or later), or apply the patched packages issued by Debian, Ubuntu, and openSUSE; VMware vROps customers should apply VMware's Application Remote Collector fix. Restrict access to the salt-master ZeroMQ ports (4505/4506) to trusted networks and review masters for signs of compromise, such as unexpected root tokens or unauthorized jobs run on minions.

Affected
SaltStack Saltall versions prior to 2019.2.4 and 3000.x prior to 3000.2
openSUSE Leap
Debian Linux
Canonical Ubuntu Linux
VMware Application Remote Collector
Estimated exposure
largetens of thousands of deployments (thousands of internet-exposed Salt masters, plus Salt bundled in Ubuntu/Debian/openSUSE and VMware ARC) — Press reports and scanning at the time found thousands of internet-exposed Salt masters ('thousands of data centers'), and the installed base is far larger because Salt ships in major Linux distributions and in VMware's Application Remote…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CISA Known Exploited Vulnerability
Affected
SaltStack Salt
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
saltstackopensusedebiancanonicalvmware
Products
salt, leap, debian linux, ubuntu linux, application remote collector
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news