Vulnerabilities > CVE-2009-2296 - Unspecified vulnerability in SUN Opensolaris and Solaris

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
sun
critical
nessus

Summary

The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.

Vulnerable Configurations

Part Description Count
OS
Sun
226

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_139991.NASL
    descriptionSunOS 5.10: nfssrv patch. Date this patch was last updated by Sun : Jun/29/09
    last seen2018-09-01
    modified2018-08-13
    plugin id38823
    published2009-05-19
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=38823
    titleSolaris 10 (sparc) : 139991-03
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_140109.NASL
    descriptionSunOS 5.10_x86: nfssrv patch. Date this patch was last updated by Sun : Jun/29/09
    last seen2018-09-01
    modified2018-08-13
    plugin id38826
    published2009-05-19
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=38826
    titleSolaris 10 (x86) : 140109-03