VDB
CVE-2025-57788
CVE-2025-57788
PUBLISHED
CVSS 6.900000095367432 MEDIUM
An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
EPSS 80.67% · 99.2th percentile
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
80.67%
99.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commvault | CommCell | 11.32.0, 11.36.0 |
| commvault | commvault | 0 |
Timeline
- Jun 28, 2025 CrowdSec Sighting
- Aug 20, 2025 CVE Published
- Aug 20, 2025 EPSS Score
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 21, 2025 PoC Published
- Aug 21, 2025 PoC Published
- Aug 22, 2025 EPSS Score
- Aug 22, 2025 PoC Published
- Aug 28, 2025 EPSS Score