CVE-2015-1497
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| persistent_systems | radia_client_automation | 7.9 | |
| persistent_systems | radia_client_automation | 8.1 | |
| persistent_systems | radia_client_automation | 9.0 | |
| persistent_systems | radia_client_automation | 9.1 | |
References
- http://osvdb.org/show/osvdb/118382
- http://packetstormsecurity.com/files/130459/HP-Client-Automation-Command-Injection.html
- http://www.exploit-db.com/exploits/36169
- http://www.exploit-db.com/exploits/36206
- http://www.securityfocus.com/bid/72612
- http://www.zerodayinitiative.com/advisories/ZDI-15-038/
- https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features
- https://www.exploit-db.com/exploits/40491/
- http://osvdb.org/show/osvdb/118382
- http://packetstormsecurity.com/files/130459/HP-Client-Automation-Command-Injection.html
- http://www.exploit-db.com/exploits/36169
- http://www.exploit-db.com/exploits/36206
- http://www.securityfocus.com/bid/72612
- http://www.zerodayinitiative.com/advisories/ZDI-15-038/
- https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features
- https://www.exploit-db.com/exploits/40491/
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.