Vulnerability record · CVE-2003-0722 · published 22 September 2003
CVE-2003-0722: Solaris sadmind weak AUTH_SYS authentication allows root compromise
Sun · Solaris
The default sadmind installation on Solaris relies on weak AUTH_SYS authentication, letting attackers spoof Solstice AdminSuite clients. A crafted sequence of RPC packets then grants root privileges, making this a full compromise of the host.
Description
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with no authentication required and a very high EPSS score means trivial, high-impact root compromise if the service is exposed.
What it is
The default sadmind installation on Solaris relies on weak AUTH_SYS authentication, letting attackers spoof Solstice AdminSuite clients. A crafted sequence of RPC packets then grants root privileges, making this a full compromise of the host.
Impact
An attacker gains root privileges on the target Solaris system, allowing complete control over data, services and configuration.
Attack surface
Reachable over the network via RPC to sadmind; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. Local attackers can also exploit it per the description.
Exploitation
Not listed in CISA KEV and no ransomware association, but EPSS is very high (0.88765, 99.8th percentile), indicating strong likelihood of exploitation activity. Reference tags give no explicit exploit-status signal beyond a US Government Resource link.
What to do
- Apply the Sun/Solaris sadmind patch referenced in SunSolve advisory 56740 and vendor bulletins.
- Disable or stop sadmind where Solstice AdminSuite management is not required.
- Restrict RPC/sadmind access to trusted management hosts using host-based firewalls or network segmentation.
- Replace AUTH_SYS with stronger authentication or migrate off the legacy Solstice AdminSuite stack.
- Audit for unauthorized Solstice AdminSuite client registrations and RPC traffic.
Detection
- Monitor RPC traffic to sadmind (port 111/portmapper lookups and sadmind program) for anomalous client sources.
- Alert on unexpected sadmind process starts or Solstice AdminSuite client registrations.
- Review Solaris audit and syslog for privilege escalation or root-level RPC activity from non-management hosts.
- Baseline and alert on new root sessions or su/root logins correlated with sadmind RPC bursts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0722 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0722), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.