← Vulnerability feed

Vulnerability record · CVE-2005-1825 · published 3 May 2005

CVE-2005-1825: HP Radia Notify Daemon nvd_exec stack buffer overflow

Hp · Radia Client

HP Radia Notify Daemon (formerly Novadigm) contains multiple stack-based buffer overflows in the nvd_exec function. A remote attacker can send a command with crafted parameters to a RADEXECD process and trigger memory corruption. The flaw affects versions 2.x, 3.x, and 4.x, including 3.1.2.0, so a wide installed base is exposed.

7.5 CVSS 2.0 High EPSS 62% · top 0.9%
7.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit references and very high EPSS, though not in KEV and with no CVSS v3 score available.

What it is

HP Radia Notify Daemon (formerly Novadigm) contains multiple stack-based buffer overflows in the nvd_exec function. A remote attacker can send a command with crafted parameters to a RADEXECD process and trigger memory corruption. The flaw affects versions 2.x, 3.x, and 4.x, including 3.1.2.0, so a wide installed base is exposed.

Impact

Successful exploitation allows arbitrary code execution in the context of the RADEXECD process, giving the attacker control of the affected host. Because the vector is network-reachable and unauthenticated, this can lead to full compromise of the system.

Attack surface

The flaw is reached over the network by sending a crafted command to a RADEXECD process, per the AV:N vector. No authentication or user interaction is required (Au:N, AC:L).

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.61522 (99.1st percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit and Vendor Advisory, so public exploit code exists.

What to do

  • Apply the vendor patch or upgrade Radia Notify Daemon to a fixed release; confirm the fixed version with HP since the record does not name one.
  • If patching is not possible, restrict network access to RADEXECD ports to trusted management hosts only.
  • Segment or firewall the Radia infrastructure so RADEXECD is not reachable from untrusted networks.
  • Monitor vendor advisories for updated guidance and validate that all 2.x, 3.x, and 4.x instances are accounted for.
  • Where the daemon is not required, disable or uninstall it to remove the attack surface.

Detection

  • Monitor network traffic to RADEXECD ports for malformed or oversized command parameters.
  • Inspect host logs and process behavior for crashes or unexpected child processes spawned by RADEXECD.
  • Alert on unexpected outbound connections or process creation originating from the Radia Notify Daemon service.
  • Use endpoint detection to flag buffer-overflow-style crashes in nvd_exec or related Radia binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1825 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-1825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.