CVE-2020-14871
Oracle Solaris and Zettabyte File System (ZFS): Unspecified
As of , CVE-2020-14871 in Oracle Solaris and Zettabyte File System (ZFS) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 3 November 2021
- US federal deadline
- 3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.80Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
- Public exploit
- 1 Metasploit module and 3 Exploit-DB entries
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.
CISA's description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
The CVE record's description, from oracle
- CVE published
- 21 October 2020
- Assigned by
- oracle
- CVSS
- 10.0 Critical (CVSS 3.1, from the CNA)
- CWE-787
- Out-of-bounds Write
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 49261).
- Exploit-DB published an exploit (EDB-ID 49896).
- Exploit-DB published an exploit (EDB-ID 50039).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflowexploit module, rank normal
- Exploit-DB: Solaris SunSSH 11.0 x86 - libpam Remote Root (3)EDB-ID 50039, 21 June 2021
- Exploit-DB: Solaris SunSSH 11.0 x86 - libpam Remote Root (2)EDB-ID 49896, 21 May 2021
- Exploit-DB: Solaris SunSSH 11.0 x86 - libpam Remote RootEDB-ID 49261, 15 December 2020
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org