Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-34028

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.676
EPSS Ranking 98.5%
CVSS Severity
CVSS v3 Score 10.0
Proposed Action
Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.
Ransomware Campaign
Unknown
Products affected by CVE-2025-34028


Contact Us

Shodan ® - All rights reserved