PT-2020-3262 · Oracle · Oracle Solaris

Larry W. Cashdollar

·

Published

2020-07-15

·

Updated

2020-09-26

·

CVE-2020-14724

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11
Description The issue is related to insufficient input validation in the Device Driver Utility component of Oracle Solaris. This can be exploited to impact the confidentiality, integrity, and availability of protected information. The vulnerability is easily exploitable and can be compromised by a low-privileged attacker with logon to the infrastructure where Oracle Solaris is executed. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of Oracle Solaris.
Recommendations For Oracle Solaris version 11, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the Device Driver Utility component until a patch is available.

Fix

Improper Privilege Management

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03570
CVE-2020-14724

Affected Products

Oracle Solaris