CVE-2015-7709
high · 10The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
10
CVSS
79.0%
EPSS (exploit prob.)
100th
EPSS percentile
2015-10-05
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| arkeia | western_digital_arkeia | <= 11.0.12 |
Check a specific version with /api/v1/cve/match.
References
- http://www.rapid7.com/db/modules/exploit/multi/misc/arkeia_agent_exec
- https://packetstormsecurity.com/files/132660/Western-Digital-Arkeia-11.0.13-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/37600/
- http://www.rapid7.com/db/modules/exploit/multi/misc/arkeia_agent_exec
- https://packetstormsecurity.com/files/132660/Western-Digital-Arkeia-11.0.13-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/37600/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-7709