VDB
CVE-2025-34028
CVE-2025-34028
PUBLISHED
KEV
CVSS 9.300000190734863 CRITICAL
A path traversal vulnerability in Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files, which, when expanded by the target server, result in Remote Code Execution. This issue affects Command Center Innovation Release: 11.38.
EPSS 97.66% · 99.9th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
97.66%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| commvault | commvault | 11.38.0, 11.38.0 |
| Commvault | Command Center Innovation Release | 11.38.0 |
Timeline
- Mar 28, 2023 CrowdSec Sighting
- Apr 5, 2023 CrowdSec Sighting
- Apr 12, 2023 CrowdSec Sighting
- Apr 26, 2023 CrowdSec Sighting
- May 18, 2023 CrowdSec Sighting
- Jun 8, 2023 CrowdSec Sighting
- Jun 16, 2023 CrowdSec Sighting
- Jul 9, 2023 CrowdSec Sighting
- Aug 3, 2023 CrowdSec Sighting
- Aug 10, 2023 CrowdSec Sighting
- Oct 15, 2023 CrowdSec Sighting
- Nov 23, 2023 CrowdSec Sighting
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34028 advisory
- https://documentation.commvault.com/securityadvisories/CV_2025_04_1.html vendor-advisory
- https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/ exploit
- https://github.com/watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028 exploit
- https://www.vulncheck.com/advisories/commvault-command-center-innovation-release-unauthenticated-install-package-path-traversal third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-34028 advisory
- https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028 url
- Nuclei Template exploit