CVE-2009-3853

IBM Tivoli Storage Manager 5.3-5.3.6.6, 5.4-5.4.2, 5.5-5.5.2.1, 6.1-6.1.0.1 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-3853. PoCs published by Metasploit, jduck, including Metasploit module exploits/windows/misc/ibm_tsm_cad_ping.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service via a malformed 'ping' packet. It leverages SEH overwrite for arbitrary code execution, requiring the service to be in a specific state (CadWaitingStatus = 1).

Description

Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16421

This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service via a malformed 'ping' packet. It leverages SEH overwrite for arbitrary code execution, requiring the service to be in a specific state (CadWaitingStatus = 1).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM Tivoli Storage Manager Express 5.3.6.2
No auth needed
Prerequisites: TSM Express CAD Service in CadWaitingStatus = 1 state · Network access to port 1582
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_tsm_cad_ping.rb

This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service by sending a maliciously crafted 'ping' packet with an oversized string, leading to arbitrary code execution. The exploit leverages SEH overwrites and requires the service to be in a specific state (CadWaitingStatus = 1).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: IBM Tivoli Storage Manager Express 5.3.6.2
No auth needed
Prerequisites: TSM Express CAD Service in CadWaitingStatus = 1 state · Network access to TCP port 1582
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory x_refsource_misc
http://secunia.com/secunia_research/2008-51/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023136
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3132
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507654/100/0/threaded
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21405562
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32534

Scores

EPSS 0.3672
EPSS Percentile 98.3%

Details

CWE
CWE-119
Status published
Products (24)
ibm/tivoli_storage_manager 5.2.5.3
ibm/tivoli_storage_manager 5.3
ibm/tivoli_storage_manager 5.3.0
ibm/tivoli_storage_manager 5.3.1
ibm/tivoli_storage_manager 5.3.2
ibm/tivoli_storage_manager 5.3.2.4
ibm/tivoli_storage_manager 5.3.3 (2 CPE variants)
ibm/tivoli_storage_manager 5.3.4 (2 CPE variants)
ibm/tivoli_storage_manager 5.3.5
ibm/tivoli_storage_manager 5.3.5.1
... and 14 more
Published Nov 04, 2009
Tracked Since Feb 18, 2026