Vulnerability record · CVE-2015-1497 · published 16 February 2015
CVE-2015-1497: Radia Client Automation radexecd.exe remote command injection
PPersistent Systems · Radia Client Automation
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0 and 9.1 fails to safely handle crafted requests, allowing code injection (CWE-94). A remote, unauthenticated attacker can send a malicious request to TCP port 3465 and execute arbitrary commands on the host. The flaw is rated CVSS 2.0 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), so it is a full compromise of confidentiality, integrity and availability.
Description
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 base score of 10.0, public exploit code and very high EPSS probability make this an urgent exposure wherever port 3465 is reachable.
What it is
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0 and 9.1 fails to safely handle crafted requests, allowing code injection (CWE-94). A remote, unauthenticated attacker can send a malicious request to TCP port 3465 and execute arbitrary commands on the host. The flaw is rated CVSS 2.0 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), so it is a full compromise of confidentiality, integrity and availability.
Impact
An attacker gains arbitrary command execution on the RCA endpoint or server running radexecd.exe, typically with the privileges of that service. That allows full control of the host, data theft, tampering and use as a pivot into the managed estate.
Attack surface
Reached over the network via a crafted request to TCP port 3465; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. Any host exposing that port to an untrusted network is directly reachable.
Exploitation
Public exploit code exists (Packet Storm and Exploit-DB references tagged Exploit), and EPSS is very high at 0.751 (99.5th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented in the record.
What to do
- Apply the vendor fix: Accelerite/Persistent Systems released solutions and best practices for the RBAC and Remote Notify features; upgrade or patch RCA to a corrected build.
- Restrict TCP port 3465 with host and network firewalls so only trusted management infrastructure can reach radexecd.exe.
- Segment RCA management traffic onto a dedicated, access-controlled network and remove direct internet exposure of the service.
- Where the service is not needed, disable radexecd.exe or the Remote Notify/RBAC functionality.
- Monitor vendor advisories for the affected 7.9, 8.1, 9.0 and 9.1 branches, which are legacy and may no longer receive fixes.
Detection
- Monitor network flows and IDS/IPS signatures for unexpected inbound connections to TCP port 3465, especially from non-management subnets.
- Audit radexecd.exe process behavior for child processes or command shells spawned by the service, which would indicate injected command execution.
- Review RCA service logs and host process-creation telemetry for anomalous commands originating from the radexecd.exe process context.
- Baseline which hosts legitimately run RCA and alert on port 3465 exposure discovered by internal or external scanning.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1497 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.