Vulnerability record · CVE-2020-5847 · published 16 March 2020
CVE-2020-5847: Unraid unauthenticated remote code execution as root
Unraid · Unraid
Unraid through 6.8.0 contains a remote code execution flaw that is reachable without authentication, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the referenced exploit title describing an authentication bypass leading to arbitrary code execution as root. The record gives no root-cause detail beyond an 'Other' CWE, so the exact vulnerable component is not specified. It matters because a network-reachable, pre-auth RCE on a storage/NAS host gives an attacker full control of the device and its data.
Description
Unraid through 6.8.0 allows Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth network RCE as root on an internet-exposed appliance, with KEV listing and near-maximum EPSS.
What it is
Unraid through 6.8.0 contains a remote code execution flaw that is reachable without authentication, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the referenced exploit title describing an authentication bypass leading to arbitrary code execution as root. The record gives no root-cause detail beyond an 'Other' CWE, so the exact vulnerable component is not specified. It matters because a network-reachable, pre-auth RCE on a storage/NAS host gives an attacker full control of the device and its data.
Impact
An attacker gains arbitrary code execution with root privileges on the Unraid host, allowing full compromise of the system, its stored data and any attached services.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector and the referenced authentication-bypass exploit. The specific exposed service or endpoint is not identified in the record.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS is very high (0.958, 99.9th percentile); public exploit references are tagged Exploit. No known ransomware campaign use is recorded.
What to do
- Upgrade Unraid to a version later than 6.8.0 per vendor instructions; the record does not enumerate fixed versions.
- Restrict network access to the Unraid web interface and management ports to trusted hosts only.
- Place the Unraid host behind a firewall or VPN rather than exposing it directly to the internet.
- Monitor vendor announcements for the applicable fixed release and confirm the upgrade completed.
Detection
- Hunt for unexpected outbound connections or new processes spawned by the Unraid web service.
- Review web server and application logs for requests matching the published authentication-bypass exploit pattern.
- Alert on new or modified files in web-accessible directories and on unexpected root-level command execution.
- Monitor for authentication anomalies or access to management endpoints from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5847 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Unraid Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157275/Unraid-6.8.0-Authentication-Bypass-Arbitrary-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.unraid.net/forum/7-announcements/ | Release NotesVendor Advisory |
| https://sysdream.com/news/lab/ | Third Party Advisory |
| https://sysdream.com/news/lab/2020-02-06-cve-2020-5847-cve-2020-5849-unraid-6-8-0-unauthenticated-remote-code-execution- | Broken LinkExploitThird Party Advisory |
| http://packetstormsecurity.com/files/157275/Unraid-6.8.0-Authentication-Bypass-Arbitrary-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.unraid.net/forum/7-announcements/ | Release NotesVendor Advisory |
| https://sysdream.com/news/lab/ | Third Party Advisory |
| https://sysdream.com/news/lab/2020-02-06-cve-2020-5847-cve-2020-5849-unraid-6-8-0-unauthenticated-remote-code-execution- | Broken LinkExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5847 | US Government Resource |
Track CVE-2020-5847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5847), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.