VDB

CVE-2025-34028

CVE-2025-34028 PUBLISHED KEV CVSS 9.300000190734863 CRITICAL

A path traversal vulnerability in Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files, which, when expanded by the target server, result in Remote Code Execution. This issue affects Command Center Innovation Release: 11.38.

EPSS 97.66% · 99.9th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
97.66%
99.9th percentile

Affected Products

VendorProductVersions
commvaultcommvault11.38.0, 11.38.0
CommvaultCommand Center Innovation Release11.38.0

Timeline

  • Mar 28, 2023 CrowdSec Sighting
  • Apr 5, 2023 CrowdSec Sighting
  • Apr 12, 2023 CrowdSec Sighting
  • Apr 26, 2023 CrowdSec Sighting
  • May 18, 2023 CrowdSec Sighting
  • Jun 8, 2023 CrowdSec Sighting
  • Jun 16, 2023 CrowdSec Sighting
  • Jul 9, 2023 CrowdSec Sighting
  • Aug 3, 2023 CrowdSec Sighting
  • Aug 10, 2023 CrowdSec Sighting
  • Oct 15, 2023 CrowdSec Sighting
  • Nov 23, 2023 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›