CVE-2018-3057 is a high-severity vulnerability affecting the Sun ZFS Storage Appliance Kit (AK) prior to version 8.7.18, specifically within its API frameworks. A highly privileged attacker with logon access to the infrastructure where the AK executes can exploit this vulnerability. Successful exploitation can lead to a complete takeover of the Sun ZFS Storage Appliance Kit, with significant impacts on confidentiality, integrity, and availability, and potential cascading effects on other products. Despite its high CVSS score of 8.2, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.7.18CPE matchmatch criteria | cpe:2.3:a:oracle:sun_zfs_storage_appliance_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.