CVE-2015-7709
Last modified
CVE-2015-7709 is a vulnerability of currently unknown severity. The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.. EPSS estimates a 78.97% chance of exploitation in the next 30 days.
Description
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arkeia | Western Digital Arkeia | <= 11.0.12 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7709?
How severe is CVE-2015-7709?
How do I fix CVE-2015-7709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7703The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x be…7.5
- CVE-2015-7704The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4…7.5
- CVE-2015-7705The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.…9.8
- CVE-2015-7706Multiple cross-site scripting (XSS) vulnerabilities in Secur…
- CVE-2015-7707Ignite Realtime Openfire 3.10.2 allows remote authenticated …
- CVE-2015-7708Cross-site scripting (XSS) vulnerability in 4images 1.7.11 a…
- CVE-2015-7711Cross-site scripting (XSS) vulnerability in popuphelp.php in…
- CVE-2015-7712Multiple eval injection vulnerabilities in mods/_standard/gr…
- CVE-2015-7713OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x…
- CVE-2015-7714Multiple SQL injection vulnerabilities in the Realtyna RPL (…7.2
- CVE-2015-7715Cross-site request forgery (CSRF) vulnerability in the Realt…8.8
- CVE-2015-7716libstagefright in Android 5.x before 5.1.1 LMY48T allows rem…
Are you affected by CVE-2015-7709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
