PT-2017-3429 · Commvault · Commvault Edge

Claudio Moletta

·

Published

2017-03-16

·

Updated

2019-12-11

·

CVE-2017-3195

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Commvault Edge versions prior to 11 SP7 Commvault Edge version 11 SP6 with hotfix prior to 590
Description The issue is caused by a stack-based buffer overflow in the Communications Service of the Commvault Edge data backup software. This could allow a remote attacker to execute arbitrary code with root/SYSTEM privileges using TCP port 8400.
Recommendations For Commvault Edge versions prior to 11 SP7, update to version 11 SP7 or later. For Commvault Edge version 11 SP6, apply hotfix 590 or later.

Exploit

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00217
CVE-2017-3195

Affected Products

Commvault Edge