Persistent Systems Radia Client Automation Agent Command Injection

critical Nessus Plugin ID 86148

Synopsis

The Persistent Systems Radia Client Automation agent listening on the remote port is affected by a command injection vulnerability.

Description

The Persistent Systems Radia Client Automation (formerly HP Client Automation) agent listening on the remote port is affected by a command execution vulnerability due to a flaw in the radexecd.exe component. An unauthenticated, remote attacker can exploit this to execute arbitrary commands with SYSTEM privileges.

Solution

See the vendor advisory for a possible solution.

See Also

http://www.nessus.org/u?ce7789b9

https://www.zerodayinitiative.com/advisories/ZDI-15-364/

Plugin Details

Severity: Critical

ID: 86148

File Name: radexecd_cmd_injection.nasl

Version: 1.9

Type: remote

Agent: windows

Family: Windows

Published: 9/25/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:persistent_systems:radia_client_automation, cpe:/a:hp:client_automation_enterprise

Required KB Items: Services/radexecd

Excluded KB Items: global_settings/supplied_logins_only

Vulnerability Publication Date: 7/20/2015