PT-2025-33899 · Commvault · Commvault

Published

2025-08-20

·

Updated

2025-08-22

·

CVE-2025-57789

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Commvault versions prior to 11.36.60
Description: An issue was discovered in Commvault that allows remote attackers to exploit default credentials to gain administrative control during the brief period between installation and the first administrator login. This exploitation is limited to the setup phase, before any jobs have been configured.
Recommendations: Update to version 11.36.60 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57789

Affected Products

Commvault