
Find real vulnerabilities before they ship
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
| Base Score | 4.6 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |