CVE-2020-5847: Unraid Remote Code Execution Vulnerability
Published Mar 16, 2020
·Updated
Unraid through 6.8.0 allows Remote Code Execution.
Other sources
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
— CISA
Affected Software
3 affected components
Unraid Unraid
Unraid Unraid<=6.8.0
Unraid Unraid<=6.8.0
Event History
Mar 16, 2020
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Apr 4, 58454
Event
05:08 AM
Frequently Asked Questions
1
What is CVE-2020-5847?
CVE-2020-5847 is a vulnerability in Unraid that allows for remote code execution with root privileges.
2
Who is affected by CVE-2020-5847?
Users of Unraid version 6.8.0 or earlier are affected by CVE-2020-5847.
3
What is the severity of CVE-2020-5847?
CVE-2020-5847 has a severity rating of 9.8 (critical).
4
How can CVE-2020-5847 be exploited?
CVE-2020-5847 can be exploited by abusing the insecure use of the extract PHP function.
5
Are there any known fixes for CVE-2020-5847?
It is recommended to upgrade Unraid to a version that includes the necessary security patches to fix CVE-2020-5847.