The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote malicious users to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sun solaris |