CVE-2020-5847

CRITICAL(9.8)KEVLikely Exploited

Unraid Remote Code Execution Vulnerability

Description

CVE-2020-5847 is a critical remote code execution vulnerability affecting Unraid through version 6.8.0. The vulnerability arises from the insecure use of the PHP extract function, which allows an attacker to execute arbitrary code as root on the underlying system. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 93.51% (99.8th percentile), this vulnerability has a near-certain probability of exploitation. Notably, this vulnerability is chainable with CVE-2020-5849 for initial unauthenticated access, significantly increasing the overall risk.

KEV Information

Vendor
Unraid
Product
Unraid
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

Affected Products

VendorProductVersion
unraidunraid<= 6.8.0

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

No specific CWE has been assigned to CVE-2020-5847 by NVD. The vulnerability stems from insecure use of the PHP extract function, which allows external input to overwrite internal variables, leading to remote code execution. This class of weakness relates to improper handling of user-controlled input in dynamic variable assignment.

Learn more: CVE-2020-5847 — NVD Detail

Impact Analysis

CVE-2020-5847 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum severity level. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication, and needs no user interaction to trigger. Successful exploitation grants the attacker complete control over the system, compromising confidentiality, integrity, and availability with the ability to execute code as root. The EPSS score of 93.51% places this vulnerability in the 99.8th percentile, indicating near-certain exploitation activity. Organizations running Unraid version 6.8.0 or earlier face critical operational risk, as the vulnerability enables full system takeover without any prior credentials when chained with CVE-2020-5849.

Exploit Maturity

Public exploit code is available for CVE-2020-5847 via Packet Storm Security, which provides a combined authentication bypass and arbitrary code execution exploit. CISA has confirmed active exploitation in the wild by listing this vulnerability in the Known Exploited Vulnerabilities catalog. The EPSS score of 93.51% (99.8th percentile) indicates near-certain exploitation activity. When combined with CVE-2020-5849, an authentication bypass vulnerability, the attack becomes fully unauthenticated, allowing remote attackers to achieve root-level code execution without any prior credentials.

Remediation

  1. Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Upgrade Unraid to a version newer than 6.8.0 that addresses this vulnerability.
  2. Verify that all Unraid instances in your environment have been updated beyond version 6.8.0, checking for both CVE-2020-5847 and the related CVE-2020-5849 authentication bypass.
  3. Restrict network access to the Unraid web management interface using firewall rules, ensuring it is not exposed to the internet or untrusted networks.
  4. Monitor Unraid server logs for indicators of compromise, including unexpected process execution, unauthorized file modifications, and suspicious network connections from the management interface.
  5. Implement network segmentation to isolate NAS and storage infrastructure from general network traffic, reducing the attack surface for management interfaces.

Technical Details

CVE-2020-5847 exploits the insecure use of PHP’s extract() function within the Unraid web management interface. The extract() function imports variables from an array into the current symbol table, and when used with untrusted user input, allows an attacker to overwrite critical internal variables. By crafting malicious HTTP requests that manipulate these variables, an attacker can redirect code execution paths to achieve arbitrary code execution as root. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms that the vulnerability is network-accessible, trivially exploitable, and requires neither privileges nor user interaction, resulting in complete compromise of confidentiality, integrity, and availability.

Frequently Asked Questions

Is CVE-2020-5847 being actively exploited?

Yes. CVE-2020-5847 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 93.51% (99.8th percentile) indicates near-certain exploitation activity. Public exploit code combining this vulnerability with CVE-2020-5849 is readily available.

What products are affected by CVE-2020-5847?

CVE-2020-5847 affects Unraid through version 6.8.0. All Unraid installations running version 6.8.0 or earlier are vulnerable to this remote code execution vulnerability.

How do I fix CVE-2020-5847?

Apply updates per vendor instructions by upgrading Unraid beyond version 6.8.0. Additionally, restrict network access to the Unraid management interface and ensure it is not publicly accessible. Address CVE-2020-5849 simultaneously, as it enables unauthenticated access.

How severe is CVE-2020-5847?

CVE-2020-5847 has a CVSS 3.1 score of 9.8 (CRITICAL), the highest practical severity rating. Combined with its near-certain exploitation probability (EPSS 93.51%) and the ability to chain with CVE-2020-5849 for unauthenticated access, this vulnerability requires immediate remediation.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score95.84%
EPSS Percentile99.9%

Dates

PublishedMarch 16, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.