← Vulnerability feed

Vulnerability record · CVE-2015-1497 · published 16 February 2015

CVE-2015-1497: Radia Client Automation radexecd.exe remote command injection

PPersistent Systems · Radia Client Automation

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0 and 9.1 fails to safely handle crafted requests, allowing code injection (CWE-94). A remote, unauthenticated attacker can send a malicious request to TCP port 3465 and execute arbitrary commands on the host. The flaw is rated CVSS 2.0 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), so it is a full compromise of confidentiality, integrity and availability.

10.0 CVSS 2.0 High EPSS 75% · top 0.5% CWE-94 · Code injection
10.0CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS 2.0 base score of 10.0, public exploit code and very high EPSS probability make this an urgent exposure wherever port 3465 is reachable.

What it is

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0 and 9.1 fails to safely handle crafted requests, allowing code injection (CWE-94). A remote, unauthenticated attacker can send a malicious request to TCP port 3465 and execute arbitrary commands on the host. The flaw is rated CVSS 2.0 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), so it is a full compromise of confidentiality, integrity and availability.

Impact

An attacker gains arbitrary command execution on the RCA endpoint or server running radexecd.exe, typically with the privileges of that service. That allows full control of the host, data theft, tampering and use as a pivot into the managed estate.

Attack surface

Reached over the network via a crafted request to TCP port 3465; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. Any host exposing that port to an untrusted network is directly reachable.

Exploitation

Public exploit code exists (Packet Storm and Exploit-DB references tagged Exploit), and EPSS is very high at 0.751 (99.5th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented in the record.

What to do

  • Apply the vendor fix: Accelerite/Persistent Systems released solutions and best practices for the RBAC and Remote Notify features; upgrade or patch RCA to a corrected build.
  • Restrict TCP port 3465 with host and network firewalls so only trusted management infrastructure can reach radexecd.exe.
  • Segment RCA management traffic onto a dedicated, access-controlled network and remove direct internet exposure of the service.
  • Where the service is not needed, disable radexecd.exe or the Remote Notify/RBAC functionality.
  • Monitor vendor advisories for the affected 7.9, 8.1, 9.0 and 9.1 branches, which are legacy and may no longer receive fixes.

Detection

  • Monitor network flows and IDS/IPS signatures for unexpected inbound connections to TCP port 3465, especially from non-management subnets.
  • Audit radexecd.exe process behavior for child processes or command shells spawned by the service, which would indicate injected command execution.
  • Review RCA service logs and host process-creation telemetry for anomalous commands originating from the radexecd.exe process context.
  • Baseline which hosts legitimately run RCA and alert on port 3465 exposure discovered by internal or external scanning.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1497 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-1498Persistent systems radia client automation permissions and access controls vulnerabilityPersistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user …EPSS 2.3%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2015-1497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.