Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-34028

98
FAUCET Score

CVE-2025-34028 is a critical Remote Code Execution (RCE) vulnerability affecting Commvault Command Center Innovation Release versions 11.38.0 to 11.38.20. This flaw allows an unauthenticated attacker to upload malicious ZIP files that exploit a path traversal vulnerability, leading to complete system compromise. Rated with a CVSS score of 10.0, it is easily exploitable remotely without user interaction, and its high EPSS score indicates a strong likelihood of exploitation. The vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has publicly available exploit code, drawing significant community attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.38.0, < 11.38.20CPE matchmatch criteria
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
LOW
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
97.66%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · May 2, 2025
Nuclei: CVE-2025-34028 · Apr 27, 2025
This CVE's current EPSS score of 0.9766 is in the 99th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
qdrantpatch availablevia llm_extracted
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted

Vendor Advisories (8)

barracudallm-barracuda-9c74a6ac9e9fa48d

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
symantecllm-symantec-6bb459a6796be546

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
verbbllm-verbb-d5d0875b52f9bda6

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
consulllm-consul-a1d3aeffb54a010e

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
clamavllm-clamav-13317dcb185f3066

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
boschllm-bosch-8e0c910588158853

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
freshrssllm-freshrss-7f9d64ac666d0c75

Vulnerability in Commvault Command Center Installation

Apr 11, 2025
qdrantllm-qdrant-08d3fe5e5c97c24e

Vulnerability in Commvault Command Center Installation

Apr 11, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
documentation.commvault.com / securityadvisories/CV_2025_04_1.html
Vendor Advisory
github.com / watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
Exploit
labs.watchtowr.com / fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028
Third Party Advisory
vulncheck.com / advisories/commvault-command-center-innovation-release-unauthenticated-install-package-path-traversal
Third Party Advisory