V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-7709
CVE
CriticalConfirmedExploit available

The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authenticatio…

CVSS
10.0
Critical
EPSS
0.79
p99
Published
2015-01-01
Updated
2015-01-01
Description

The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

Tags · CWE
CWE-264
Affected products
Western_digital_arkeia ≤ 11.0.12
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.790 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
37600
exploitdb · https://www.exploit-db.com/exploits/37600
Enterprise
Affected products
ProductVendorStatus
western_digital_arkeia*Tracked
Source databases
CVE
Related vulnerabilities