CVE-2020-25592
CRITICALSaltStack Salt - Improper Authentication Bypass via eauth Credential Validation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25592.
PoCs published by KPC, wvu, including Metasploit module exploits/linux/http/saltstack_salt_api_cmd_exec.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2020-25592) and command injection (CVE-2020-16846) in SaltStack Salt's REST API to execute arbitrary commands as root. It leverages the 'ssh_priv' parameter in the REST API to inject commands, bypassing authentication via the 'eauth' parameter.
Description
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
Exploits (1)
This Metasploit module exploits an authentication bypass (CVE-2020-25592) and command injection (CVE-2020-16846) in SaltStack Salt's REST API to execute arbitrary commands as root. It leverages the 'ssh_priv' parameter in the REST API to inject commands, bypassing authentication via the 'eauth' parameter.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H