Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 10, 2022

CVE-2020-8816

High
EPSS 90.8%CISA KEV
Pi-hole/AdminLTE

Description

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

EPSS — Exploit Probability

90.8%

Higher than 99.6% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2020-8816

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
90.8%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Dec 10, 2021

Added to KEV

Dec 10, 2021

Remediation Due

Jun 10, 2022

Affected Product

Pi-hole

AdminLTE

View all Pi-hole CVEs