CVE-2025-34028 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 97.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-05-23.
Description
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 97.55% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2025-05-23 |
| Public exploit | none known |
| Published | 2025-04-22 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Commvault Command Center Path Traversal Vulnerability |
|---|---|
| Added | 2025-05-02 |
| Due | 2025-05-23 |
| Vendor / product | Commvault / Command Center |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| commvault | commvault |
| linux | linux kernel |
| microsoft | windows |
References
- https://documentation.commvault.com/securityadvisories/CV_2025_04_1.html
- https://github.com/watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
- https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/
- https://www.vulncheck.com/advisories/commvault-command-center-innovation-release-unauthenticated-install-package-path-traversal
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34028
→ the Explorer · watch your stack · NVD