PT-2021-5589 · Commvault · Commvault Commcell

Brandon Perry

+2

·

Published

2021-06-30

·

Updated

2022-01-22

·

CVE-2021-34993

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Commvault CommCell version 11.22.22
Description The issue is related to the CVSearchService service and is caused by inadequate validation prior to authentication, allowing remote attackers to bypass authentication on affected installations. This can enable an attacker to gain unauthorized access to the system without requiring authentication. The specific flaw exists within the CVSearchService service.
Recommendations For Commvault CommCell version 11.22.22, consider disabling the CVSearchService service until a patch is available to prevent exploitation. Restrict access to the CVSearchService to minimize the risk of unauthorized access. Apply proper validation prior to authentication to prevent bypassing authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00020
CVE-2021-34993
ZDI-21-1328

Affected Products

Commvault Commcell