Unauthorized Access Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2024-20959

4.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2024

Summary

An exploitable vulnerability in the Oracle ZFS Storage Appliance Kit enables a high privileged attacker with logon credentials to the infrastructure to execute unauthorized commands. This can lead to severe disruptions, such as causing the appliance to hang or crash repeatedly, resulting in a denial-of-service condition. The vulnerability affects supported versions, particularly 8.8, allowing attackers to manipulate system availability without detection.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software 8.8

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.