cbcvebase.
CVE-2020-25592
published 2020-11-06

CVE-2020-25592: In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

PriorityP181critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
57.45%
99.0th percentile
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
saltstacksalt< 2015.8.102015.8.10
saltstacksalt
saltstacksalt>= 0 < 2015.8.102015.8.10
saltstacksalt>= 0 < 2015.8.132015.8.13
saltstacksalt>= 0 < 2015.8.8+ds-1ubuntu0.1+esm22015.8.8+ds-1ubuntu0.1+esm2
saltstacksalt>= 0 < 2017.7.4+dfsg1-1ubuntu18.04.2+esm12017.7.4+dfsg1-1ubuntu18.04.2+esm1
saltstacksalt>= 2015.8.11 < 2015.8.132015.8.13
saltstacksalt>= 2015.8.11 < 2015.8.132015.8.13
saltstacksalt>= 2016.11.0 < 2016.11.32016.11.3
saltstacksalt>= 2016.11.0 < 2016.11.32016.11.3
saltstacksalt>= 2016.11.0 < 2016.11.102016.11.10
saltstacksalt>= 2016.11.4 < 2016.11.62016.11.6
saltstacksalt>= 2016.11.4 < 2016.11.62016.11.6
saltstacksalt>= 2016.11.7 < 2016.11.102016.11.10
saltstacksalt>= 2016.11.7 < 2016.11.102016.11.10
saltstacksalt>= 2016.3.0 < 2016.3.42016.3.4
saltstacksalt>= 2016.3.0 < 2016.3.42016.3.4
saltstacksalt>= 2016.3.0 < 2016.3.82016.3.8
saltstacksalt>= 2016.3.5 < 2016.3.62016.3.6
saltstacksalt>= 2016.3.5 < 2016.3.62016.3.6
saltstacksalt>= 2016.3.7 < 2016.3.82016.3.8
saltstacksalt>= 2016.3.7 < 2016.3.82016.3.8
saltstacksalt>= 2017.5.0 < 2017.7.42017.7.4

Detection & IOCsextracted from sources · hover to see the quote

path/salt/client/ssh/shell.py
path/etc/salt/master
  • Detect POST requests to /run with client=ssh and parameters ssh_priv, ssh_user (or tgt in username@localhost format), ssh_port, ssh_remote_port_forwards, or ssh_options containing shell metacharacters, indicating command injection attempts.
  • The Metasploit module exploits this vulnerability against Salt versions including 2019.2.3 and 3002 on Ubuntu 20.04.1; prioritize detection on these versions.
  • ·The rest-cherrypy netapi module is NOT enabled by default; the vulnerability is only exploitable if it has been explicitly configured in /etc/salt/master.
  • ·Salt versions through 3002 are affected; patched versions include 3000.3, 3000.4, 3001.1, 3001.2, and 3002 (with the security patch applied).
  • ·Red Hat Ceph Storage 2's salt package will not be fixed as RHSCON-2 has reached End Of Life.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.