A stack-based buffer overflow vulnerability exists in the server component of IBM Tivoli Storage Manager FastBack 6.1 prior to version 6.1.12. The flaw allows remote attackers to trigger a buffer overflow via unspecified vectors, resulting in a crash of the FastBack daemon. This vulnerability is distinct from other buffer overflow and arbitrary command execution issues reported in the same product family.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a compact exploit repo with two files: a single Python exploit script (exploit.py) and a README documenting the vulnerability and exploitation flow. The code is a real unauthenticated network RCE exploit for CVE-2015-1925 in IBM Tivoli FastBack Server 6.1.4 on Windows x86. The main exploit flow is straightforward: exploit.py accepts a target host via -t/--target, determines the attacker host IP with gethostname/gethostbyname, generates reverse-shell shellcode configured to call back to the attacker on TCP/4444, wraps that shellcode in a DEP/NX-bypass ROP chain, embeds the final payload into a custom binary packet, and sends it to the target over TCP/11460. After delivery, the script starts a listener and provides an interactive reverse shell interface. Structurally, the Exploit class contains three major capabilities: send(), which builds the proprietary packet header and vulnerable File: %s field before transmitting it to the target service; bpnx(), which constructs a ROP chain using hardcoded gadget addresses to prepare and invoke VirtualAlloc so the shellcode region becomes executable; and rvsh()/recv(), which respectively generate the Windows reverse-shell shellcode and handle the incoming callback session. The shellcode is custom-written and resolves APIs dynamically rather than relying on external payload frameworks. The exploit is operational rather than a simple proof of concept because it includes a complete payload and post-exploitation interaction path. It is not part of a common exploit framework such as Metasploit or Nuclei. The attack vector is purely network-based: a crafted packet with opcode 0x0534 is sent to the vulnerable service, which eventually reaches an sscanf-based stack overflow in the target’s packet handling path. The README indicates the overflow occurs in _FXCLI_SetConfFileChunk after dispatch from _FXCLI_OraBR_Exec_Command, with control transferred to a ROP gadget in csftpav6.dll. The ROP chain sets up a VirtualAlloc call frame, pivots execution to the shellcode, and the shellcode connects back to the attacker, spawns a command shell, and terminates the vulnerable process on exit. Notable fingerprintable artifacts include the target TCP port 11460, the reverse callback port 4444, the protocol opcode 0x0534, the packet string template 'File: %s From: 0 To: 0 ChunkLoc: 0 FileLoc: 0', and references to FastBackServer.exe, csftpav6.dll, kernel32.dll, and ws2_32.dll. Overall, the repository’s purpose is to provide a working Python-based exploit for remote code execution against a specific vulnerable FastBack Server deployment, including DEP bypass and an interactive reverse shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.