PT-2025-17556 · Commvault · Commvault Command Center
Sonny
+1
·
Published
2025-04-11
·
Updated
2026-02-16
·
CVE-2025-34028
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Commvault Command Center Innovation Release versions 11.38.0 through 11.38.19
Description
A path traversal vulnerability in Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files, which, when expanded by the target server, result in Remote Code Execution. This issue has been actively exploited, and it is recommended to patch immediately to prevent remote code execution. The vulnerability affects Commvault Command Center versions 11.38.0 to 11.38.19. Federal agencies have been directed to apply fixes by May 23, 2025.
Recommendations
For Commvault Command Center Innovation Release versions 11.38.0 through 11.38.19, update to version 11.38.20 or 11.38.25 to resolve the vulnerability. As a temporary workaround, consider restricting access to the vulnerable endpoint until a patch is applied.
Exploit
Fix
RCE
Missing Authentication
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Commvault Command Center