CVE-2015-7709
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 79%
from disclosure to weapon0 days
Published on NVDOct 5
1st PoCJul 13
metasploitJul 10
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/37600cve_referencepacketstormsecurity.com/files/132660/Western-Digital-Arkeia-11.0.13-Remote-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/37600/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.