CVE-2020-11651
CRITICAL KEVSaltStack Salt <2019.2.4,3000.2 - RCE
Title source: llmDescription
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Exploits (17)
nomisec
SCANNER
107 stars
by rossengeorgiev · remote
https://github.com/rossengeorgiev/salt-security-backports
nomisec
WORKING POC
24 stars
by ssrsec · remote
https://github.com/ssrsec/CVE-2020-11651-CVE-2020-11652-EXP
nomisec
WORKING POC
6 stars
by kevthehermit · infoleak
https://github.com/kevthehermit/CVE-2020-11651
nomisec
WORKING POC
5 stars
by lovelyjuice · poc
https://github.com/lovelyjuice/cve-2020-11651-exp-plus
nomisec
SCANNER
1 stars
by appcheck-ng · remote
https://github.com/appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652
nomisec
WORKING POC
by hardsoftsecurity · remote
https://github.com/hardsoftsecurity/CVE-2020-11651-PoC
metasploit
WORKING POC
by F-Secure, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/saltstack_salt_root_key.rb
References (12)
Scores
CVSS v3
9.8
EPSS
0.9424
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-07-22
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-0171
Status
published
Products (10)
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
opensuse/leap
15.1
pypi/salt
0 - 2019.2.4PyPI
saltstack/salt
< 2019.2.4
vmware/application_remote_collector
7.5.0
vmware/application_remote_collector
8.0.0
Published
Apr 30, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026