ZeroHour

CVE-2020-14871

KEV PoC ×3large

Pre-auth buffer overflow in Oracle Solaris PAM enables remote root takeover

CISA: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

CVSS 3.1
10.0 critical
EPSS
80%p100
Published
()
KEV added
AI analysis

CVE-2020-14871 is a critical (CVSS 10.0) out-of-bounds write (CWE-787) in the Pluggable authentication module (PAM) component of Oracle Solaris 10 and 11. An unauthenticated attacker with network access can trigger the buffer overflow via multiple protocols without credentials or user interaction; public exploits demonstrate remote root takeover through SunSSH on Solaris 11.0 x86. Because PAM is shared across many network services, successful attacks may significantly impact additional products, and the flaw is explicitly not exploitable on Solaris 11.1 and later or ZFSSA 8.7 and later. The vulnerability was added to CISA KEV on 2021-11-03, carries an EPSS of ~80% (100th percentile), and related reporting notes the threat actor UNC1945 used it as a Solaris zero-day, confirming in-the-wild exploitation.

What to do: Apply Oracle's updates per vendor instructions, as required by the CISA KEV listing, prioritizing Solaris 10 and Solaris 11.0 systems (Solaris 11.1+ and ZFSSA 8.7+ are not exploitable). Reduce exposure of internet-facing SunSSH and other PAM-backed network services on unpatched Solaris hosts, and hunt for exploitation consistent with UNC1945 activity.

Affected
Oracle SolarisSolaris 10 and 11 (not exploitable on Solaris 11.1 and later)
Oracle Zettabyte File System (ZFS) / ZFS Storage Appliance (ZFSSA)ZFSSA releases prior to 8.7 (not exploitable on 8.7 and later)
Estimated exposure
largetens of thousands of internet-exposed Solaris 10/11 systems (order of magnitude ~10,000-100,000) — Historical internet-wide scans have shown tens of thousands of Solaris hosts exposing SSH and other PAM-backed services, and Solaris 10/11 remains widely deployed in enterprise, financial and government estates; exact counts are unknown…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle Solaris and Zettabyte File System (ZFS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
solaris
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news