Vulnerability record · CVE-2015-7709 · published 5 October 2015
CVE-2015-7709: Western Digital Arkeia Backup Agent auth bypass leads to remote command execution
AArkeia · Western Digital Arkeia
The arkeiad daemon in the Western Digital Arkeia Backup Agent (11.0.12 and earlier) fails to enforce authentication on the ARKFS_EXEC_CMD operation, allowing crafted requests to run arbitrary commands. Because the daemon is reachable over the network and no credentials are required, any host that can reach the agent port can take over the system.
Description
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code and very high EPSS probability makes this an immediate patch-or-isolate priority.
What it is
The arkeiad daemon in the Western Digital Arkeia Backup Agent (11.0.12 and earlier) fails to enforce authentication on the ARKFS_EXEC_CMD operation, allowing crafted requests to run arbitrary commands. Because the daemon is reachable over the network and no credentials are required, any host that can reach the agent port can take over the system.
Impact
An unauthenticated remote attacker gains full command execution as the arkeiad service account, which typically yields complete compromise of the backup server (CVSS 2.0 base 10, C/I/A all complete).
Attack surface
Reached over the network via the arkeiad service port; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are needed, only a series of crafted requests invoking ARKFS_EXEC_CMD.
Exploitation
Public exploit code exists (Rapid7 Metasploit module, Packet Storm, Exploit-DB) and EPSS is 0.79 (99.6th percentile), though CISA KEV does not list it.
What to do
- Patch or upgrade Arkeia Backup Agent beyond 11.0.12; if no fixed release is available, retire or replace the product.
- Block network access to the arkeiad service port from untrusted networks; restrict it to the backup management subnet and trusted hosts only.
- Run the arkeiad service with a least-privilege account and isolate backup servers on a segmented management VLAN.
- Monitor for and remove any unauthorized accounts, scheduled tasks or binaries left after suspected exploitation.
Detection
- Alert on unexpected processes spawned by arkeiad, especially shells or command interpreters.
- Monitor network traffic to the arkeiad port for ARKFS_EXEC_CMD operations from hosts that are not the backup management server.
- Baseline normal arkeiad child processes and flag deviations, including outbound connections from the backup server.
- Review arkeiad and system logs for authentication bypass patterns or repeated crafted request sequences.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7709 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7709), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.