CVE-2020-14871 is a critical vulnerability in the Pluggable Authentication Module (PAM) component of Oracle Solaris versions 10 and 11, allowing unauthenticated attackers with network access to fully compromise the system. This easily exploitable flaw carries a CVSS 3.1 Base Score of 10.0, indicating severe impacts on confidentiality, integrity, and availability, potentially leading to a complete system takeover. Although not exploitable in Solaris 11.1+ and ZFSSA 8.7+, it is actively exploited in the wild, with multiple Metasploit modules and ExploitDB entries available. The high EPSS score, FAUCET Risk Score, and significant media coverage underscore its severe risk and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10, < 11.1CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.