Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Thousands of Servers Are Affected by the Flaw on SaltStack

Explore Thousands of Servers Are Affected by the Flaw on with a clear summary of the key facts, context, and practical details readers should know.

Table of Contents

This article provides a clear overview of Thousands of Servers Are Affected by the Flaw on SaltStack, with the main facts, useful context, and practical details organized for easy reading.

Accordingly, this vulnerability allows hackers to execute arbitrary code remotely on servers located in data centers or on cloud platforms.
The flaw was discovered by researchers at F-Secure in early March and announced in early May, shortly after SaltStack released and encouraged users to update to the new patch. A special patch for SaltStack Salt before 2019.2.4 was also released.
SaltStack is an open source software, used for configuration management and a tool to remotely control applications on the enterprise server, operating with the client-server model. Where a command server is called a master, and the server that receives commands from the master server with different operating systems is called a minion.
In order to successfully exploit this vulnerability, hackers used a combination of two error codes, namely CVE-2020-11651 and CVE-2020-11652, that exist in versions 3000.1 and earlier of SaltStack to interfere with data exchange between the master server and the minion servers in it. CVE-2020-11651 is a vulnerability to bypass authentication and collect tokens of users while CVE-2020-11652 is a vulnerability that allows unauthorized access or control of directories through failure to control input variables..
If other vulnerabilities after being exploited only impact on the server that exists, the vulnerability of SaltStack RCE can affect the whole server in the system with a much greater impact level. Hacked hackers can bypass authentication and collect control keys of minion machines with the highest user rights, and can gain unauthorized control of directories, gaining full control over not only the master server but also with all minion machines. From there, an attacker can illegally install malicious programs, bitcoin mining software, even install on spyware or cryptographic malware to extort data.
Given the aforementioned degree of danger and scale, SaltStack RCE was rated extremely serious and was scored 9.8 / 10 by the Advisory Board's Common Vulnerability Scoring System (CVSS). The infrastructure is part of the Department of Homeland Security.
VSEC experts recommend users to install automatic update mode for SaltStack to ensure the system always uses the latest security patches. Tighten access to the master server, narrow the range of devices that can access the SaltStack 4505 and 4506 default ports.
Begin Dable In_article Widget / For inquiries, visit http://dable. io
End Dable In_article Widget / For inquiries, visit http://dable. io

FAQ

What is the main focus of Thousands of Servers Are Affected by the Flaw on SaltStack?

The article explains the most important facts, context, and practical details related to Thousands of Servers Are Affected by the Flaw on SaltStack.

Who may find this information useful?

It is useful for readers who want a clear overview, practical context, and a better understanding of the subject.

What should readers verify before taking action?

Check current product versions, official requirements, regional availability, and any details that may have changed since the original publication.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.