CVE-2020-5847
Unraid ≤ 6.8.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2020-5847 is a critical-severity an unspecified weakness vulnerability in Unraid Unraid. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 0.1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2020-5847 is a remote code execution vulnerability affecting Unraid versions through 6.8.0. It carries a CVSS v3.1 base score of 9.8 and is classified under NVD-CWE-Other.
The flaw enables unauthenticated attackers to bypass authentication and achieve arbitrary code execution as root over the network. Public exploit code demonstrating the authentication bypass and code execution has been posted to PacketStorm.
Reference materials from Sysdream and the Unraid forums describe the issue as unauthenticated remote code execution as root in version 6.8.0, with additional technical analysis available at the listed URLs. No specific mitigation details such as patch versions or configuration changes are provided in the source data.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-27001
Vulnerability Data
Unraid through 6.8.0 allows Remote Code Execution.
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.