CVE-2015-7861
published 2015-10-19CVE-2015-7861: Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by…
PriorityP258critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.36%
91.6th percentile
Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| accelerite | radia_client_automation | — | — |
| accelerite | radia_client_automation | — | — |
| accelerite | radia_client_automation | — | — |
| accelerite | radia_client_automation | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vp9-q3c6-pqwg: Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9
ghsa_unreviewed·2022-05-17
CVE-2015-7861 [HIGH] GHSA-4vp9-q3c6-pqwg: Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9
Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling.
Cisco
Cisco IP Phone 7861 Denial of Service Vulnerability
vendor_cisco·2015-05-26·CVSS 7.8
CVE-2015-0751 [HIGH] CWE-399 Cisco IP Phone 7861 Denial of Service Vulnerability
Cisco IP Phone 7861 Denial of Service Vulnerability
A vulnerability in the Cisco IP Phone 7861 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to improper boundary restrictions when user-supplied input to the affected application is processed. An unauthenticated, remote attacker could exploit the vulnerability by sending crafted network packets to the affected device.javascript:void(0);
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks to send crafted network packets to the affected device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates throug
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.kb.cert.org/vuls/id/966927http://www.securityfocus.com/bid/75966http://www.securitytracker.com/id/1033861http://zerodayinitiative.com/advisories/ZDI-15-364/http://www.kb.cert.org/vuls/id/966927http://www.securityfocus.com/bid/75966http://www.securitytracker.com/id/1033861http://zerodayinitiative.com/advisories/ZDI-15-364/
2015-10-19
Published