CVE-2020-14871

CRITICAL KEV

Oracle Solaris 10-11 - Privilege Escalation

Title source: llm

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Exploits (6)

exploitdb WORKING POC
by Nathaniel Singer · pythonremotesolaris
https://www.exploit-db.com/exploits/50039
exploitdb WORKING POC
by legend · pythonremotesolaris
https://www.exploit-db.com/exploits/49896
exploitdb WORKING POC
by Hacker Fantastic · cremotesolaris
https://www.exploit-db.com/exploits/49261
nomisec WORKING POC 2 stars
by robidev · remote
https://github.com/robidev/CVE-2020-14871-Exploit
nomisec SCANNER
by FromPartsUnknown · dos
https://github.com/FromPartsUnknown/EvilSunCheck
metasploit WORKING POC NORMAL
by Jacob Thompson, Aaron Carreras, Jeffrey Martin, Hacker Fantastic, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/solaris/ssh/pam_username_bof.rb

Scores

CVSS v3 10.0
EPSS 0.8887
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-09-04
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-7007
CWE
CWE-787
Status published
Products (2)
oracle/solaris 9
oracle/solaris 10 - 11.1
Published Oct 21, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026