CVE-2020-25780 is a Directory Traversal vulnerability affecting Commvault CommCell versions before 14.68, 15.58, 16.44, 17.29, and 18.13. This flaw allows an unauthenticated attacker to view arbitrary files outside the intended log-files directory by manipulating log file viewing requests. Rated with a CVSS score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector and high confidentiality impact, requiring no user interaction. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detecting this Local File Inclusion vulnerability. Community discussion and media coverage are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.68CPE matchmatch criteria | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.58CPE matchmatch criteria | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.44CPE matchmatch criteria | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.29CPE matchmatch criteria | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* | ||
>= 18.0, < 18.13CPE matchmatch criteria | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.