CVE-2025-34028 is a critical Remote Code Execution (RCE) vulnerability affecting Commvault Command Center Innovation Release versions 11.38.0 to 11.38.20. This flaw allows an unauthenticated attacker to upload malicious ZIP files that exploit a path traversal vulnerability, leading to complete system compromise. Rated with a CVSS score of 10.0, it is easily exploitable remotely without user interaction, and its high EPSS score indicates a strong likelihood of exploitation. The vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has publicly available exploit code, drawing significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.38.0, < 11.38.20CPE matchmatch criteria | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025Vulnerability in Commvault Command Center Installation
Apr 11, 2025