PT-2018-1116 · Oracle · Solaris
Published
2018-01-16
·
Updated
2018-01-26
·
CVE-2018-2710
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Sun Systems Products Suite (subcomponent: Kernel) version 10
Description
The issue is related to a vulnerability in the Kernel component of the Solaris operating system, which can be exploited by an unauthenticated attacker with network access via ICMP. This vulnerability can result in the ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. The exploitation of this vulnerability is considered easily exploitable.
Recommendations
For version 10, apply the necessary security patches to fix the vulnerability in the Kernel component. As a temporary workaround, consider restricting access to ICMP protocol to minimize the risk of exploitation.
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solaris