Vulnerability record · CVE-2020-14871 · published 21 October 2020
CVE-2020-14871: Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeover
Oracle · Solaris
Oracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network without authentication. Successful exploitation can fully compromise the host, and Oracle notes attacks may significantly impact additional products. Solaris 11.1 and later and ZFSSA 8.7 and later are not exploitable, which is why Oracle assigned a 0.0 base score for those releases.
Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network reachability, full host takeover, public exploit code and CISA KEV listing make this an urgent patching priority for any exposed Solaris 10/11 system.
What it is
Oracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network without authentication. Successful exploitation can fully compromise the host, and Oracle notes attacks may significantly impact additional products. Solaris 11.1 and later and ZFSSA 8.7 and later are not exploitable, which is why Oracle assigned a 0.0 base score for those releases.
Impact
An unauthenticated network attacker can achieve remote code execution and full takeover of the affected Solaris system, with high confidentiality, integrity and availability impact. Because the scope is changed, connected or dependent products may also be compromised.
Attack surface
Reached over the network via multiple protocols (CVSS AV:N, AC:L, PR:N, UI:N); no authentication or user interaction is required. Public exploit write-ups specifically target SunSSH and the PAM parse_user_name buffer overflow.
Exploitation
CVE-2020-14871 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of about 0.80 (99.6th percentile). Multiple references are tagged Exploit, indicating public exploit code exists; no ransomware campaign use is documented.
What to do
- Apply the Oracle October 2020 CPU patches for Solaris 10 and 11 immediately; confirm 11.1+ and ZFSSA 8.7+ are not affected.
- If patching cannot be completed, restrict network access to SSH and other PAM-dependent services on affected Solaris hosts to trusted management networks.
- Disable or tightly firewall unnecessary network services that invoke PAM authentication on Solaris 10/11 systems.
- Monitor Oracle and CISA advisories for updated patches and required actions tied to the KEV entry.
- Inventory all Solaris 10 and 11 hosts, including appliances, to ensure none remain unpatched.
Detection
- Hunt for exploitation attempts against SunSSH/PAM by reviewing SSH and authentication logs for malformed usernames, crashes or unexpected root sessions on Solaris 10/11.
- Monitor for unexpected processes, new listening services or privilege changes on Solaris hosts that could indicate post-exploitation.
- Use network detection to flag anomalous or oversized authentication payloads to Solaris SSH and other PAM-backed services.
- Correlate host telemetry with known public exploit indicators from the Packetstorm and oss-security references.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-14871 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-14871 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14871), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.