Vulnerability record · CVE-2005-1825 · published 3 May 2005
CVE-2005-1825: HP Radia Notify Daemon nvd_exec stack buffer overflow
Hp · Radia Client
HP Radia Notify Daemon (formerly Novadigm) contains multiple stack-based buffer overflows in the nvd_exec function. A remote attacker can send a command with crafted parameters to a RADEXECD process and trigger memory corruption. The flaw affects versions 2.x, 3.x, and 4.x, including 3.1.2.0, so a wide installed base is exposed.
Description
Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit references and very high EPSS, though not in KEV and with no CVSS v3 score available.
What it is
HP Radia Notify Daemon (formerly Novadigm) contains multiple stack-based buffer overflows in the nvd_exec function. A remote attacker can send a command with crafted parameters to a RADEXECD process and trigger memory corruption. The flaw affects versions 2.x, 3.x, and 4.x, including 3.1.2.0, so a wide installed base is exposed.
Impact
Successful exploitation allows arbitrary code execution in the context of the RADEXECD process, giving the attacker control of the affected host. Because the vector is network-reachable and unauthenticated, this can lead to full compromise of the system.
Attack surface
The flaw is reached over the network by sending a crafted command to a RADEXECD process, per the AV:N vector. No authentication or user interaction is required (Au:N, AC:L).
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.61522 (99.1st percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit and Vendor Advisory, so public exploit code exists.
What to do
- Apply the vendor patch or upgrade Radia Notify Daemon to a fixed release; confirm the fixed version with HP since the record does not name one.
- If patching is not possible, restrict network access to RADEXECD ports to trusted management hosts only.
- Segment or firewall the Radia infrastructure so RADEXECD is not reachable from untrusted networks.
- Monitor vendor advisories for updated guidance and validate that all 2.x, 3.x, and 4.x instances are accounted for.
- Where the daemon is not required, disable or uninstall it to remove the attack surface.
Detection
- Monitor network traffic to RADEXECD ports for malformed or oversized command parameters.
- Inspect host logs and process behavior for crashes or unexpected child processes spawned by RADEXECD.
- Alert on unexpected outbound connections or process creation originating from the Radia Notify Daemon service.
- Use endpoint detection to flag buffer-overflow-style crashes in nvd_exec or related Radia binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1825 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.