CVE-2020-14871

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
References
Link Resource
http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html Exploit Third Party Advisory VDB Entry
http://www.openwall.com/lists/oss-security/2021/03/03/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/03/03/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/07/03/3 Mailing List Patch
http://www.openwall.com/lists/oss-security/2024/07/03/3 Mailing List Patch
https://www.oracle.com/security-alerts/cpuoct2020.html Vendor Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:oracle:solaris:9:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*

History

07 Feb 2025, 14:45

Type Values Removed Values Added
CVSS v2 : 10.0
v3 : 10.0
v2 : 10.0
v3 : unknown
References (MISC) http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html - Third Party Advisory, VDB Entry
References (MISC) http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html - Exploit, Third Party Advisory, VDB Entry
References (MLIST) http://www.openwall.com/lists/oss-security/2021/03/03/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2021/03/03/1 - Mailing List, Third Party Advisory
References (MISC) https://www.oracle.com/security-alerts/cpuoct2020.html - Vendor Advisory () https://www.oracle.com/security-alerts/cpuoct2020.html - Vendor Advisory
References (MISC) http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html - Exploit, Third Party Advisory, VDB Entry

14 Aug 2024, 20:09

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/07/03/3 - () http://www.openwall.com/lists/oss-security/2024/07/03/3 - Mailing List, Patch

03 Jul 2024, 09:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/07/03/3 -

Information

Published : 2020-10-21 15:15

Updated : 2025-02-07 14:45


NVD link : CVE-2020-14871

Mitre link : CVE-2020-14871


JSON object : View

Products Affected

oracle

  • solaris
CWE
CWE-787

Out-of-bounds Write