PT-2017-15946 · Oracle · Solaris
Published
2017-04-24
·
Updated
2019-10-03
·
CVE-2017-3510
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Sun Systems Products Suite version 11.3
Description
The issue affects the Kernel Zones virtualized NIC driver in the Solaris component, allowing a low-privileged attacker with network access via multiple protocols to compromise Solaris. This can result in unauthorized creation, deletion, or modification access to critical data or all Solaris accessible data. The impact of successful attacks may extend beyond Solaris to other products.
Recommendations
For version 11.3, update to a version that includes the fix for this issue to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris