PT-2017-3429 · Commvault · Commvault Edge
Claudio Moletta
·
Published
2017-03-16
·
Updated
2019-12-11
·
CVE-2017-3195
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Commvault Edge versions prior to 11 SP7
Commvault Edge version 11 SP6 with hotfix prior to 590
Description
The issue is caused by a stack-based buffer overflow in the Communications Service of the Commvault Edge data backup software. This could allow a remote attacker to execute arbitrary code with root/SYSTEM privileges using TCP port 8400.
Recommendations
For Commvault Edge versions prior to 11 SP7, update to version 11 SP7 or later.
For Commvault Edge version 11 SP6, apply hotfix 590 or later.
Exploit
Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Commvault Edge