CVE-2020-14871

Scores

EPSS

0.889high88.9%
0%20%40%60%80%100%

Percentile: 88.9%

CVSS

10.0critical3.x
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 3.x
10.0

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-787

Related Vulnerabilities

Exploits

Exploit ID: CVE-2020-14871

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploit ID: 49261

Source: exploitdb

URL: https://www.exploit-db.com/exploits/49261

Exploit ID: 49896

Source: exploitdb

URL: https://www.exploit-db.com/exploits/49896

Exploit ID: 50039

Source: exploitdb

URL: https://www.exploit-db.com/exploits/50039

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: solaris

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*",      "versionEndExcluding": "11.1",      "versionStartIncluding": "10",      "vulnerable": true    },    { ...

Source: nvd

End of list