← Vulnerability feed

Vulnerability record · CVE-2020-14871 · published 21 October 2020

CVE-2020-14871: Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeover

Oracle · Solaris

Oracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network without authentication. Successful exploitation can fully compromise the host, and Oracle notes attacks may significantly impact additional products. Solaris 11.1 and later and ZFSSA 8.7 and later are not exploitable, which is why Oracle assigned a 0.0 base score for those releases.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 80% · top 0.4% CWE-787 · Out-of-bounds write
10.0CVSS 3.1 base score, v2 10.0
80%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network reachability, full host takeover, public exploit code and CISA KEV listing make this an urgent patching priority for any exposed Solaris 10/11 system.

What it is

Oracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network without authentication. Successful exploitation can fully compromise the host, and Oracle notes attacks may significantly impact additional products. Solaris 11.1 and later and ZFSSA 8.7 and later are not exploitable, which is why Oracle assigned a 0.0 base score for those releases.

Impact

An unauthenticated network attacker can achieve remote code execution and full takeover of the affected Solaris system, with high confidentiality, integrity and availability impact. Because the scope is changed, connected or dependent products may also be compromised.

Attack surface

Reached over the network via multiple protocols (CVSS AV:N, AC:L, PR:N, UI:N); no authentication or user interaction is required. Public exploit write-ups specifically target SunSSH and the PAM parse_user_name buffer overflow.

Exploitation

CVE-2020-14871 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of about 0.80 (99.6th percentile). Multiple references are tagged Exploit, indicating public exploit code exists; no ransomware campaign use is documented.

What to do

  • Apply the Oracle October 2020 CPU patches for Solaris 10 and 11 immediately; confirm 11.1+ and ZFSSA 8.7+ are not affected.
  • If patching cannot be completed, restrict network access to SSH and other PAM-dependent services on affected Solaris hosts to trusted management networks.
  • Disable or tightly firewall unnecessary network services that invoke PAM authentication on Solaris 10/11 systems.
  • Monitor Oracle and CISA advisories for updated patches and required actions tied to the KEV entry.
  • Inventory all Solaris 10 and 11 hosts, including appliances, to ensure none remain unpatched.

Detection

  • Hunt for exploitation attempts against SunSSH/PAM by reviewing SSH and authentication logs for malformed usernames, crashes or unexpected root sessions on Solaris 10/11.
  • Monitor for unexpected processes, new listening services or privilege changes on Solaris hosts that could indicate post-exploitation.
  • Use network detection to flag anomalous or oversized authentication payloads to Solaris SSH and other PAM-backed services.
  • Correlate host telemetry with known public exploit indicators from the Packetstorm and oss-security references.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-14871 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/03/03/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2024/07/03/3 Mailing ListPatch
https://www.oracle.com/security-alerts/cpuoct2020.html Vendor Advisory
http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/03/03/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2024/07/03/3 Mailing ListPatch
https://www.oracle.com/security-alerts/cpuoct2020.html Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14871 US Government Resource

Track CVE-2020-14871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-3010Oracle Solaris XScreenSaver local privilege escalationA flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the sy…KEVEPSS 13%analysed8.8CVE-2015-4495Firefox PDF reader same-origin bypass allows file read and privilege gainThe PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, l…KEVEPSS 69%analysed7.8CVE-2008-2992Adobe Acrobat and Reader util.printf Stack Buffer OverflowAdobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is pas…KEVEPSS 98%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed10.0CVE-2026-46978Oracle solaris improper access control vulnerabilityVulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11…EPSS 0.43%10.0CVE-2017-3623Oracle solaris vulnerabilityVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see …EPSS 22%10.0CVE-2015-8104Xen vulnerabilityThe KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2020-14871), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.