CVE-2017-3623, also known as "Ebbisland," is a critical vulnerability in the Kernel RPC subcomponent of Oracle Solaris, specifically affecting Solaris 10 systems that have not applied specific patches or updates since January 2012. This easily exploitable vulnerability allows an unauthenticated attacker with network access to achieve complete system takeover, impacting confidentiality, integrity, and availability. With a CVSS 3.0 score of 10.0, it presents a severe risk. While not in CISA's KEV catalog, an exploit (EDB-47888) is publicly available, and it has garnered significant community discussion, indicating potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.