Cyber Resilience

CVE-2020-11651

Debian Linux 10.0 … 9.0

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
30 April 2020
Modified
07 November 2025
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.97 99.9th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2020-11651 is a critical-severity an unspecified weakness vulnerability in Debian Debian Linux. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability CVE-2020-11651 is an authentication bypass flaw in SaltStack Salt versions before 2019.2.4 and 3000 before 3000.2. It exists in the salt-master process ClearFuncs class, which does not properly validate method calls and thereby exposes certain methods to remote access without authentication.

An unauthenticated remote attacker can invoke the exposed methods to retrieve user tokens stored on the salt master or to execute arbitrary commands on connected salt minions. The issue carries a CVSS 3.1 base score of 9.8 reflecting network-accessible attack complexity with high impact to confidentiality, integrity, and availability.

Publicly referenced advisories, including those from openSUSE and VMware, and exploit artifacts on PacketStormSecurity indicate that the primary mitigation is to upgrade affected Salt installations to the fixed releases 2019.2.4 or 3000.2. Proof-of-concept code demonstrating unauthenticated remote code execution against both masters and minions has been published.

EU & UK References

Vulnerability Data

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used…

more

to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2020-11652Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2020-16846Same product: Debian Debian Linuxboth on KEV
CVE-2016-3714Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2010-4344Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2010-4345Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2018-6789Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2019-10149Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2022-0543Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2025-32463Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2016-1646Same product: Canonical Ubuntu Linuxboth on KEV

Affected Assets

saltstack
salt
≤ 2019.2.4 · 3000 — 3000.2
opensuse
leap
15.1
debian
debian linux
10.0, 8.0, 9.0
canonical
ubuntu linux
16.04, 18.04
vmware
application remote collector
7.5.0, 8.0.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References