PT-2001-2508 · Oracle · Solaris
Published
2001-10-09
·
Updated
2018-10-30
·
CVE-2001-1414
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Solaris versions 2.5.1, 2.6, 7, and 8
Description
The issue concerns the Basic Security Module (BSM) for Solaris, which fails to log anonymous FTP access. This allows remote attackers to conceal their activities, particularly when specific BSM audit files are missing under the FTP root.
Recommendations
For Solaris versions 2.5.1, 2.6, 7, and 8, consider configuring the BSM to log anonymous FTP access or implement an alternative auditing mechanism to monitor FTP activities.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris