CVE-2015-1497

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:persistent_systems:radia_client_automation:7.9:*:*:*:*:*:*:*
cpe:2.3:a:persistent_systems:radia_client_automation:8.1:*:*:*:*:*:*:*
cpe:2.3:a:persistent_systems:radia_client_automation:9.0:*:*:*:*:*:*:*
cpe:2.3:a:persistent_systems:radia_client_automation:9.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:25

Type Values Removed Values Added
References () http://osvdb.org/show/osvdb/118382 - () http://osvdb.org/show/osvdb/118382 -
References () http://packetstormsecurity.com/files/130459/HP-Client-Automation-Command-Injection.html - Exploit () http://packetstormsecurity.com/files/130459/HP-Client-Automation-Command-Injection.html - Exploit
References () http://www.exploit-db.com/exploits/36169 - Exploit () http://www.exploit-db.com/exploits/36169 - Exploit
References () http://www.exploit-db.com/exploits/36206 - Exploit () http://www.exploit-db.com/exploits/36206 - Exploit
References () http://www.securityfocus.com/bid/72612 - () http://www.securityfocus.com/bid/72612 -
References () http://www.zerodayinitiative.com/advisories/ZDI-15-038/ - () http://www.zerodayinitiative.com/advisories/ZDI-15-038/ -
References () https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features - () https://support.accelerite.com/hc/en-us/articles/203659814-Accelerite-releases-solutions-and-best-practices-to-enhance-the-security-for-RBAC-and-Remote-Notify-features -
References () https://www.exploit-db.com/exploits/40491/ - () https://www.exploit-db.com/exploits/40491/ -

Information

Published : 2015-02-16 15:59

Updated : 2024-11-21 02:25


NVD link : CVE-2015-1497

Mitre link : CVE-2015-1497

CVE.ORG link : CVE-2015-1497


JSON object : View

Products Affected

persistent_systems

  • radia_client_automation
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')