⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..

CVE-2020-14871Out-of-bounds Write in Oracle Solaris

CWE-787Out-of-bounds Write10 documents8 sources
Severity
10.0CRITICALNVD
EPSS
88.9%
top 0.48%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 21
KEV addedNov 3
KEV dueMay 3
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is n

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages2 packages

NVDoracle/solaris1011.1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7pcp-8fjh-246q: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module)2022-05-24
CVEList
CVE-2020-14871: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module)2020-10-21
VulnCheck
Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability2020

💥Exploits & PoCs

3
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root (3)2021-06-21
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root (2)2021-05-21
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root2020-12-15

📋Vendor Advisories

2
CISA
Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability2021-11-03
Oracle
Oracle Oracle Systems Risk Matrix: Pluggable authentication module — CVE-2020-148712020-10-15