cbcvebase.
CVE-2009-0872
published 2009-03-11

CVE-2009-0872: The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with…

PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.96%
78.0th percentile
The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.

Affected

111 ranges· showing 25
VendorProductVersion rangeFixed in
sunopensolaris<= snv_110
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.