Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Conclusion & alert: CVE-2020-14871 is rated Critical Active Threat (94.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 80.29%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2021-11-03) affecting Oracle / Solaris and Zettabyte File System (ZFS). a weakness (CWE-787) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability · CISA KEV detail
: 2021-11-03
: 2022-05-03
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 50039 | exploit_db | edb | 2021-06-21 | Exploit-DB ↗ |
| 49896 | exploit_db | edb | 2021-05-21 | Exploit-DB ↗ |
| 49261 | exploit_db | edb | 2020-12-15 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 89.80% | 80.29% | -9.51% |
| 2 | 2026-06-14 | 88.87% | 89.80% | +0.93% |
| 3 | 2025-11-21 | — | 88.87% | — |
Full EPSS history (39 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/159961/SunSSH-Solaris-10-x86-Remote-Root.html | Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/160510/Solaris-SunSSH-11.0-x86-libpam-Remote-Root.html | Exploit Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/160609/Oracle-Solaris-SunSSH-PAM-parse_user_name-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/163232/Solaris-SunSSH-11.0-Remote-Root.html | Exploit Third Party Advisory VDB Entry |
| http://www.openwall.com/lists/oss-security/2021/03/03/1 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/07/03/3 | Mailing List Patch |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14871 | US Government Resource |