PT-2001-2508 · Oracle · Solaris

Published

2001-10-09

·

Updated

2018-10-30

·

CVE-2001-1414

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Solaris versions 2.5.1, 2.6, 7, and 8
Description The issue concerns the Basic Security Module (BSM) for Solaris, which fails to log anonymous FTP access. This allows remote attackers to conceal their activities, particularly when specific BSM audit files are missing under the FTP root.
Recommendations For Solaris versions 2.5.1, 2.6, 7, and 8, consider configuring the BSM to log anonymous FTP access or implement an alternative auditing mechanism to monitor FTP activities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1414

Affected Products

Solaris