CVE-2009-0873 - CVE House
Back to Database
Status published Medium CVE-2009-0873

The NFS daemon (aka nfsd) in Sun Solaris 10 and...

Vulnerability Description

The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0873

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

opensolaris, sunos, solaris
Vulnerable Versions:
snv_01, snv_02, snv_03, snv_04, snv_05, snv_06, snv_07, snv_08, snv_09, snv_10, snv_20, snv_21, snv_22, snv_23, snv_24, snv_25, snv_26, snv_27, snv_28, snv_29, snv_30, snv_31, snv_32, snv_33, snv_34, snv_35, snv_36, snv_37, snv_38, snv_39, snv_40, snv_41, snv_42, snv_43, snv_44, snv_45, snv_46, snv_47, snv_48, snv_49, snv_50, snv_51, snv_52, snv_53, snv_54, snv_55, snv_56, snv_57, snv_58, snv_59, snv_60, snv_61, snv_62, snv_63, snv_64, snv_65, snv_66, snv_67, snv_68, snv_69, snv_70, snv_71, snv_72, snv_73, snv_74, snv_75, snv_76, snv_77, snv_78, snv_79, snv_80, snv_81, snv_82, snv_83, snv_84, snv_85, snv_86, snv_87, snv_88, snv_89, snv_90, snv_91, snv_92, snv_93, snv_94, snv_95, snv_96, snv_97, snv_98, snv_99, 5.10, 10.0

Timeline

Official Publish: March 11th, 2009
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.