ZeroHour

CVE-2020-5847

KEV PoC ×2large

Unauthenticated Remote Code Execution as Root in Unraid Through 6.8.0

CISA: Unraid Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
96%p100
Published
()
KEV added
AI analysis

Unraid versions through 6.8.0 are vulnerable to unauthenticated remote code execution: an attacker with network access to the server's web management interface can bypass authentication and execute arbitrary code with root privileges. The attack requires no credentials, special conditions, or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any internet-exposed or otherwise reachable Unraid server is directly exploitable. Successful exploitation gives an attacker full root-level control of the server, enabling data theft, malware or ransomware deployment, and persistence on the host. All Unraid deployments up to and including 6.8.0 are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), public proof-of-concept exploits have been available since February 2020, and EPSS assigns a ~96% probability of exploitation in the next 30 days; ransomware-specific use is currently unknown.

What to do: Upgrade all Unraid servers to a release newer than 6.8.0 per vendor instructions, as required by the CISA KEV catalog. Until patched, restrict the Unraid web management interface to trusted networks (VPN or firewall rules) and do not expose it directly to the internet. Because exploitation yields root access, review patched-but-previously-exposed servers for signs of compromise such as unexpected processes, new user accounts or cron entries, and unfamiliar outbound connections.

Affected
Unraidall releases through and including 6.8.0
Estimated exposure
largetens of thousands of internet-exposed Unraid servers; hundreds of thousands of total installations — Unraid is a widely deployed self-hosted NAS/home-server operating system with a large hobbyist and prosumer user base, and public internet scans have shown thousands to tens of thousands of Unraid web management interfaces exposed online.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unraid through 6.8.0 allows Remote Code Execution.

CISA Known Exploited Vulnerability
Affected
Unraid Unraid
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
unraid
Products
unraid
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.