cbcvebase.
CVE-2009-0873
published 2009-03-11

CVE-2009-0873: The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes…

PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.96%
78.0th percentile
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

Affected

92 ranges· showing 25
VendorProductVersion rangeFixed in
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
sunopensolaris
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.