CVE-2010-0271
hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/opensolaris
- Source
- cve@mitre.org
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-274830-1Vendor Advisory
- http://www.securityfocus.com/bid/37656
- http://www.securitytracker.com/id?1023416
- http://www.vupen.com/english/advisories/2010/0076
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55461
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-274830-1Vendor Advisory
- http://www.securityfocus.com/bid/37656
- http://www.securitytracker.com/id?1023416
- http://www.vupen.com/english/advisories/2010/0076
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55461
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.