CVE-2020-14871
KEV PoC ×3largePre-auth buffer overflow in Oracle Solaris PAM enables remote root takeover
CISA: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
CVE-2020-14871 is a critical (CVSS 10.0) out-of-bounds write (CWE-787) in the Pluggable authentication module (PAM) component of Oracle Solaris 10 and 11. An unauthenticated attacker with network access can trigger the buffer overflow via multiple protocols without credentials or user interaction; public exploits demonstrate remote root takeover through SunSSH on Solaris 11.0 x86. Because PAM is shared across many network services, successful attacks may significantly impact additional products, and the flaw is explicitly not exploitable on Solaris 11.1 and later or ZFSSA 8.7 and later. The vulnerability was added to CISA KEV on 2021-11-03, carries an EPSS of ~80% (100th percentile), and related reporting notes the threat actor UNC1945 used it as a Solaris zero-day, confirming in-the-wild exploitation.
What to do: Apply Oracle's updates per vendor instructions, as required by the CISA KEV listing, prioritizing Solaris 10 and Solaris 11.0 systems (Solaris 11.1+ and ZFSSA 8.7+ are not exploitable). Reduce exposure of internet-facing SunSSH and other PAM-backed network services on unpatched Solaris hosts, and hunt for exploitation consistent with UNC1945 activity.
| Oracle Solaris | Solaris 10 and 11 (not exploitable on Solaris 11.1 and later) |
| Oracle Zettabyte File System (ZFS) / ZFS Storage Appliance (ZFSSA) | ZFSSA releases prior to 8.7 (not exploitable on 8.7 and later) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Affected
- Oracle Solaris and Zettabyte File System (ZFS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- solaris
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H