CVE-2015-7709
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 79.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 78.97% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- arkeia/western digital arkeia
- Source
- cve@mitre.org
References
- http://www.rapid7.com/db/modules/exploit/multi/misc/arkeia_agent_execExploit
- https://packetstormsecurity.com/files/132660/Western-Digital-Arkeia-11.0.13-Remote-Code-Execution.htmlExploit
- https://www.exploit-db.com/exploits/37600/Exploit
- http://www.rapid7.com/db/modules/exploit/multi/misc/arkeia_agent_execExploit
- https://packetstormsecurity.com/files/132660/Western-Digital-Arkeia-11.0.13-Remote-Code-Execution.htmlExploit
- https://www.exploit-db.com/exploits/37600/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.