CVE-2020-5849: Unraid Authentication Bypass Vulnerability
Published Mar 16, 2020
·Updated
Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
Other sources
Unraid 6.8.0 allows authentication bypass.
Affected Software
3 affected components
Unraid Unraid=6.8.0
Unraid Unraid
Unraid Unraid=6.8.0
Event History
Mar 16, 2020
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is CVE-2020-5849?
CVE-2020-5849 is an authentication bypass vulnerability in Unraid that allows attackers to gain access to the administrative interface.
2
How severe is CVE-2020-5849?
CVE-2020-5849 has a severity rating of 7.5 (high).
3
Which version of Unraid is affected by CVE-2020-5849?
Unraid version 6.8.0 is affected by CVE-2020-5849.
4
Can CVE-2020-5849 be exploited remotely?
Yes, CVE-2020-5849 can be exploited remotely.
5
Is there a fix for CVE-2020-5849?
Yes, applying the latest security updates provided by Unraid will fix CVE-2020-5849.