CVE-2015-7709: Critical severity knox software arkeia vulnerability
Published Oct 5, 2015
·Updated
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFSEXECCMD operation.
Affected Software
1 affected component
Arkeia Western Digital Arkeia<=11.0.12
Event History
Oct 5, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7709?
CVE-2015-7709 is classified as a critical vulnerability due to its potential for remote code execution without authentication.
2
How do I fix CVE-2015-7709?
To fix CVE-2015-7709, upgrade to a version of the Arkeia Backup Agent later than 11.0.12.
3
What type of attack does CVE-2015-7709 enable?
CVE-2015-7709 enables remote attackers to execute arbitrary commands on affected systems.
4
Which versions of the Arkeia Backup Agent are affected by CVE-2015-7709?
CVE-2015-7709 affects the Arkeia Backup Agent version 11.0.12 and earlier.
5
Is authentication required to exploit CVE-2015-7709?
No, CVE-2015-7709 allows attackers to bypass authentication to exploit the vulnerability.