Persistent Systems Radia Client Automation Agent Command Injection

critical Nessus Plugin ID 86427

Synopsis

The Persistent Systems Radia Client Automation agent listening on the remote port is affected by a command injection vulnerability.

Description

The Persistent Systems Radia Client Automation (formerly HP Client Automation) agent listening on the remote port is affected by a command execution vulnerability due to a flaw in the radexecd.exe component. An unauthenticated, remote attacker can exploit this to execute arbitrary commands in the context of the radexecd process.

Solution

See the vendor advisory for a possible solution.

See Also

http://www.nessus.org/u?56b928e5

https://www.zerodayinitiative.com/advisories/ZDI-15-038/

Plugin Details

Severity: Critical

ID: 86427

File Name: radexecd_cve-2015-1497.nasl

Version: 1.9

Type: remote

Family: General

Published: 10/19/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:persistent_systems:radia_client_automation, cpe:/a:hp:client_automation_enterprise

Required KB Items: Services/radexecd

Excluded KB Items: global_settings/supplied_logins_only

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 2/10/2015

Exploitable With

Core Impact

Metasploit (HP Client Automation Command Injection)

Reference Information

CVE: CVE-2015-1497

BID: 72612