Junglewise Threat Intelligence

CVE-2020-14871: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

CVE-2020-14871 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle Solaris. Vendors: Oracle.

Executive brief

A critical out-of-bounds write vulnerability in the Pluggable Authentication Module (PAM) component of Oracle Solaris allows unauthenticated attackers to compromise the system via multiple protocols. Successful exploitation can lead to a complete takeover of the affected Oracle Solaris or ZFS Storage Appliance systems.

Affected products

  • Oracle Solaris 10, 11 (prior to 11.1)
  • Oracle ZFS Storage Appliance Kit Prior to 8.7

Timeline

  • 2020-10-20: advisory: Initial Oracle security alert published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2021-11-03: disclosed: NVD publication date
  • 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog

Related threats