CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2015-7709 Western Digital Arkeia Backup Agent arkeiad OS Command Injection Vulnerability

2016年11月29日 1896点热度 0人点赞 0条评论

漏洞类别:General remote services

漏洞等级:

漏洞信息

Western Digital Arkeia is a fast, easy-to-use, and affordable solution for network backup. WD Arkeia backup servers can be deployed as a software application, a physical appliance, or a virtual appliance.

Western Digital Arkeia Virtual Appliance is exposed to Remote Command Execution vulnerability as the arkeiad daemon in the Arkeia Backup Agent allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

Affected Versions:
Western Digital Arkeia 11.0.12 and earlier

漏洞危害

Remote attackers could exploit this vulnerability to execute arbitrary commands on the system.

解决方案

The vendor has not released a patch to fix this vulnerability. Please contact Arkeia to fix this vulnerability. Workaround:
Restrict access to port 617 where possible.

0day

标签: 暂无
最后更新:2016年11月30日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me