Vulnerability Details CVE-2025-3928
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.116
EPSS Ranking 93.3%
CVSS Severity
CVSS v3 Score 8.8
Proposed Action
Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.
Ransomware Campaign
Unknown
Products affected by CVE-2025-3928
-
cpe:2.3:a:commvault:commvault:11.20.0
-
cpe:2.3:a:commvault:commvault:11.20.10
-
cpe:2.3:a:commvault:commvault:11.20.100
-
cpe:2.3:a:commvault:commvault:11.20.101
-
cpe:2.3:a:commvault:commvault:11.20.102
-
cpe:2.3:a:commvault:commvault:11.20.104
-
cpe:2.3:a:commvault:commvault:11.20.105
-
cpe:2.3:a:commvault:commvault:11.20.106
-
cpe:2.3:a:commvault:commvault:11.20.107
-
cpe:2.3:a:commvault:commvault:11.20.108
-
cpe:2.3:a:commvault:commvault:11.20.11
-
cpe:2.3:a:commvault:commvault:11.20.110
-
cpe:2.3:a:commvault:commvault:11.20.111
-
cpe:2.3:a:commvault:commvault:11.20.112
-
cpe:2.3:a:commvault:commvault:11.20.113
-
cpe:2.3:a:commvault:commvault:11.20.114
-
cpe:2.3:a:commvault:commvault:11.20.115
-
cpe:2.3:a:commvault:commvault:11.20.116
-
cpe:2.3:a:commvault:commvault:11.20.117
-
cpe:2.3:a:commvault:commvault:11.20.118
-
cpe:2.3:a:commvault:commvault:11.20.119
-
cpe:2.3:a:commvault:commvault:11.20.12
-
cpe:2.3:a:commvault:commvault:11.20.120
-
cpe:2.3:a:commvault:commvault:11.20.121
-
cpe:2.3:a:commvault:commvault:11.20.122
-
cpe:2.3:a:commvault:commvault:11.20.123
-
cpe:2.3:a:commvault:commvault:11.20.124
-
cpe:2.3:a:commvault:commvault:11.20.125
-
cpe:2.3:a:commvault:commvault:11.20.128
-
cpe:2.3:a:commvault:commvault:11.20.129
-
cpe:2.3:a:commvault:commvault:11.20.13
-
cpe:2.3:a:commvault:commvault:11.20.130
-
cpe:2.3:a:commvault:commvault:11.20.131
-
cpe:2.3:a:commvault:commvault:11.20.132
-
cpe:2.3:a:commvault:commvault:11.20.133
-
cpe:2.3:a:commvault:commvault:11.20.134
-
cpe:2.3:a:commvault:commvault:11.20.135
-
cpe:2.3:a:commvault:commvault:11.20.136
-
cpe:2.3:a:commvault:commvault:11.20.137
-
cpe:2.3:a:commvault:commvault:11.20.139
-
cpe:2.3:a:commvault:commvault:11.20.14
-
cpe:2.3:a:commvault:commvault:11.20.142
-
cpe:2.3:a:commvault:commvault:11.20.143
-
cpe:2.3:a:commvault:commvault:11.20.145
-
cpe:2.3:a:commvault:commvault:11.20.146
-
cpe:2.3:a:commvault:commvault:11.20.147
-
cpe:2.3:a:commvault:commvault:11.20.148
-
cpe:2.3:a:commvault:commvault:11.20.149
-
cpe:2.3:a:commvault:commvault:11.20.150
-
cpe:2.3:a:commvault:commvault:11.20.152
-
cpe:2.3:a:commvault:commvault:11.20.154
-
cpe:2.3:a:commvault:commvault:11.20.156
-
cpe:2.3:a:commvault:commvault:11.20.157
-
cpe:2.3:a:commvault:commvault:11.20.158
-
cpe:2.3:a:commvault:commvault:11.20.160
-
cpe:2.3:a:commvault:commvault:11.20.161
-
cpe:2.3:a:commvault:commvault:11.20.162
-
cpe:2.3:a:commvault:commvault:11.20.163
-
cpe:2.3:a:commvault:commvault:11.20.164
-
cpe:2.3:a:commvault:commvault:11.20.165
-
cpe:2.3:a:commvault:commvault:11.20.166
-
cpe:2.3:a:commvault:commvault:11.20.167
-
cpe:2.3:a:commvault:commvault:11.20.168
-
cpe:2.3:a:commvault:commvault:11.20.17
-
cpe:2.3:a:commvault:commvault:11.20.170
-
cpe:2.3:a:commvault:commvault:11.20.171
-
cpe:2.3:a:commvault:commvault:11.20.172
-
cpe:2.3:a:commvault:commvault:11.20.174
-
cpe:2.3:a:commvault:commvault:11.20.176
-
cpe:2.3:a:commvault:commvault:11.20.18
-
cpe:2.3:a:commvault:commvault:11.20.180
-
cpe:2.3:a:commvault:commvault:11.20.182
-
cpe:2.3:a:commvault:commvault:11.20.183
-
cpe:2.3:a:commvault:commvault:11.20.185
-
cpe:2.3:a:commvault:commvault:11.20.186
-
cpe:2.3:a:commvault:commvault:11.20.188
-
cpe:2.3:a:commvault:commvault:11.20.189
-
cpe:2.3:a:commvault:commvault:11.20.19
-
cpe:2.3:a:commvault:commvault:11.20.191
-
cpe:2.3:a:commvault:commvault:11.20.192
-
cpe:2.3:a:commvault:commvault:11.20.193
-
cpe:2.3:a:commvault:commvault:11.20.196
-
cpe:2.3:a:commvault:commvault:11.20.199
-
cpe:2.3:a:commvault:commvault:11.20.20
-
cpe:2.3:a:commvault:commvault:11.20.200
-
cpe:2.3:a:commvault:commvault:11.20.202
-
cpe:2.3:a:commvault:commvault:11.20.204
-
cpe:2.3:a:commvault:commvault:11.20.207
-
cpe:2.3:a:commvault:commvault:11.20.209
-
cpe:2.3:a:commvault:commvault:11.20.21
-
cpe:2.3:a:commvault:commvault:11.20.212
-
cpe:2.3:a:commvault:commvault:11.20.213
-
cpe:2.3:a:commvault:commvault:11.20.22
-
cpe:2.3:a:commvault:commvault:11.20.23
-
cpe:2.3:a:commvault:commvault:11.20.24
-
cpe:2.3:a:commvault:commvault:11.20.25
-
cpe:2.3:a:commvault:commvault:11.20.26
-
cpe:2.3:a:commvault:commvault:11.20.27
-
cpe:2.3:a:commvault:commvault:11.20.28
-
cpe:2.3:a:commvault:commvault:11.20.29
-
cpe:2.3:a:commvault:commvault:11.20.3
-
cpe:2.3:a:commvault:commvault:11.20.30
-
cpe:2.3:a:commvault:commvault:11.20.31
-
cpe:2.3:a:commvault:commvault:11.20.32
-
cpe:2.3:a:commvault:commvault:11.20.33
-
cpe:2.3:a:commvault:commvault:11.20.34
-
cpe:2.3:a:commvault:commvault:11.20.35
-
cpe:2.3:a:commvault:commvault:11.20.36
-
cpe:2.3:a:commvault:commvault:11.20.37
-
cpe:2.3:a:commvault:commvault:11.20.38
-
cpe:2.3:a:commvault:commvault:11.20.39
-
cpe:2.3:a:commvault:commvault:11.20.40
-
cpe:2.3:a:commvault:commvault:11.20.41
-
cpe:2.3:a:commvault:commvault:11.20.42
-
cpe:2.3:a:commvault:commvault:11.20.43
-
cpe:2.3:a:commvault:commvault:11.20.44
-
cpe:2.3:a:commvault:commvault:11.20.45
-
cpe:2.3:a:commvault:commvault:11.20.46
-
cpe:2.3:a:commvault:commvault:11.20.47
-
cpe:2.3:a:commvault:commvault:11.20.48
-
cpe:2.3:a:commvault:commvault:11.20.49
-
cpe:2.3:a:commvault:commvault:11.20.51
-
cpe:2.3:a:commvault:commvault:11.20.52
-
cpe:2.3:a:commvault:commvault:11.20.53
-
cpe:2.3:a:commvault:commvault:11.20.54
-
cpe:2.3:a:commvault:commvault:11.20.55
-
cpe:2.3:a:commvault:commvault:11.20.56
-
cpe:2.3:a:commvault:commvault:11.20.57
-
cpe:2.3:a:commvault:commvault:11.20.58
-
cpe:2.3:a:commvault:commvault:11.20.59
-
cpe:2.3:a:commvault:commvault:11.20.6
-
cpe:2.3:a:commvault:commvault:11.20.60
-
cpe:2.3:a:commvault:commvault:11.20.61
-
cpe:2.3:a:commvault:commvault:11.20.62
-
cpe:2.3:a:commvault:commvault:11.20.63
-
cpe:2.3:a:commvault:commvault:11.20.64
-
cpe:2.3:a:commvault:commvault:11.20.65
-
cpe:2.3:a:commvault:commvault:11.20.66
-
cpe:2.3:a:commvault:commvault:11.20.67
-
cpe:2.3:a:commvault:commvault:11.20.7
-
cpe:2.3:a:commvault:commvault:11.20.71
-
cpe:2.3:a:commvault:commvault:11.20.72
-
cpe:2.3:a:commvault:commvault:11.20.73
-
cpe:2.3:a:commvault:commvault:11.20.74
-
cpe:2.3:a:commvault:commvault:11.20.75
-
cpe:2.3:a:commvault:commvault:11.20.76
-
cpe:2.3:a:commvault:commvault:11.20.77
-
cpe:2.3:a:commvault:commvault:11.20.78
-
cpe:2.3:a:commvault:commvault:11.20.79
-
cpe:2.3:a:commvault:commvault:11.20.80
-
cpe:2.3:a:commvault:commvault:11.20.81
-
cpe:2.3:a:commvault:commvault:11.20.82
-
cpe:2.3:a:commvault:commvault:11.20.84
-
cpe:2.3:a:commvault:commvault:11.20.85
-
cpe:2.3:a:commvault:commvault:11.20.86
-
cpe:2.3:a:commvault:commvault:11.20.87
-
cpe:2.3:a:commvault:commvault:11.20.88
-
cpe:2.3:a:commvault:commvault:11.20.89
-
cpe:2.3:a:commvault:commvault:11.20.9
-
cpe:2.3:a:commvault:commvault:11.20.90
-
cpe:2.3:a:commvault:commvault:11.20.91
-
cpe:2.3:a:commvault:commvault:11.20.92
-
cpe:2.3:a:commvault:commvault:11.20.93
-
cpe:2.3:a:commvault:commvault:11.20.94
-
cpe:2.3:a:commvault:commvault:11.20.95
-
cpe:2.3:a:commvault:commvault:11.20.96
-
cpe:2.3:a:commvault:commvault:11.20.97
-
cpe:2.3:a:commvault:commvault:11.20.98
-
cpe:2.3:a:commvault:commvault:11.20.99
-
cpe:2.3:a:commvault:commvault:11.28.0
-
cpe:2.3:a:commvault:commvault:11.28.1
-
cpe:2.3:a:commvault:commvault:11.28.10
-
cpe:2.3:a:commvault:commvault:11.28.100
-
cpe:2.3:a:commvault:commvault:11.28.101
-
cpe:2.3:a:commvault:commvault:11.28.102
-
cpe:2.3:a:commvault:commvault:11.28.104
-
cpe:2.3:a:commvault:commvault:11.28.105
-
cpe:2.3:a:commvault:commvault:11.28.106
-
cpe:2.3:a:commvault:commvault:11.28.107
-
cpe:2.3:a:commvault:commvault:11.28.108
-
cpe:2.3:a:commvault:commvault:11.28.109
-
cpe:2.3:a:commvault:commvault:11.28.11
-
cpe:2.3:a:commvault:commvault:11.28.110
-
cpe:2.3:a:commvault:commvault:11.28.111
-
cpe:2.3:a:commvault:commvault:11.28.112
-
cpe:2.3:a:commvault:commvault:11.28.113
-
cpe:2.3:a:commvault:commvault:11.28.114
-
cpe:2.3:a:commvault:commvault:11.28.115
-
cpe:2.3:a:commvault:commvault:11.28.116
-
cpe:2.3:a:commvault:commvault:11.28.117
-
cpe:2.3:a:commvault:commvault:11.28.119
-
cpe:2.3:a:commvault:commvault:11.28.12
-
cpe:2.3:a:commvault:commvault:11.28.120
-
cpe:2.3:a:commvault:commvault:11.28.121
-
cpe:2.3:a:commvault:commvault:11.28.122
-
cpe:2.3:a:commvault:commvault:11.28.123
-
cpe:2.3:a:commvault:commvault:11.28.124
-
cpe:2.3:a:commvault:commvault:11.28.125
-
cpe:2.3:a:commvault:commvault:11.28.126
-
cpe:2.3:a:commvault:commvault:11.28.127
-
cpe:2.3:a:commvault:commvault:11.28.128
-
cpe:2.3:a:commvault:commvault:11.28.13
-
cpe:2.3:a:commvault:commvault:11.28.130
-
cpe:2.3:a:commvault:commvault:11.28.131
-
cpe:2.3:a:commvault:commvault:11.28.132
-
cpe:2.3:a:commvault:commvault:11.28.133
-
cpe:2.3:a:commvault:commvault:11.28.134
-
cpe:2.3:a:commvault:commvault:11.28.135
-
cpe:2.3:a:commvault:commvault:11.28.137
-
cpe:2.3:a:commvault:commvault:11.28.14
-
cpe:2.3:a:commvault:commvault:11.28.15
-
cpe:2.3:a:commvault:commvault:11.28.16
-
cpe:2.3:a:commvault:commvault:11.28.17
-
cpe:2.3:a:commvault:commvault:11.28.18
-
cpe:2.3:a:commvault:commvault:11.28.19
-
cpe:2.3:a:commvault:commvault:11.28.2
-
cpe:2.3:a:commvault:commvault:11.28.20
-
cpe:2.3:a:commvault:commvault:11.28.23
-
cpe:2.3:a:commvault:commvault:11.28.24
-
cpe:2.3:a:commvault:commvault:11.28.3
-
cpe:2.3:a:commvault:commvault:11.28.32
-
cpe:2.3:a:commvault:commvault:11.28.33
-
cpe:2.3:a:commvault:commvault:11.28.34
-
cpe:2.3:a:commvault:commvault:11.28.35
-
cpe:2.3:a:commvault:commvault:11.28.36
-
cpe:2.3:a:commvault:commvault:11.28.37
-
cpe:2.3:a:commvault:commvault:11.28.4
-
cpe:2.3:a:commvault:commvault:11.28.44
-
cpe:2.3:a:commvault:commvault:11.28.45
-
cpe:2.3:a:commvault:commvault:11.28.48
-
cpe:2.3:a:commvault:commvault:11.28.49
-
cpe:2.3:a:commvault:commvault:11.28.5
-
cpe:2.3:a:commvault:commvault:11.28.50
-
cpe:2.3:a:commvault:commvault:11.28.51
-
cpe:2.3:a:commvault:commvault:11.28.52
-
cpe:2.3:a:commvault:commvault:11.28.53
-
cpe:2.3:a:commvault:commvault:11.28.54
-
cpe:2.3:a:commvault:commvault:11.28.55
-
cpe:2.3:a:commvault:commvault:11.28.56
-
cpe:2.3:a:commvault:commvault:11.28.58
-
cpe:2.3:a:commvault:commvault:11.28.59
-
cpe:2.3:a:commvault:commvault:11.28.60
-
cpe:2.3:a:commvault:commvault:11.28.63
-
cpe:2.3:a:commvault:commvault:11.28.64
-
cpe:2.3:a:commvault:commvault:11.28.65
-
cpe:2.3:a:commvault:commvault:11.28.66
-
cpe:2.3:a:commvault:commvault:11.28.68
-
cpe:2.3:a:commvault:commvault:11.28.69
-
cpe:2.3:a:commvault:commvault:11.28.70
-
cpe:2.3:a:commvault:commvault:11.28.71
-
cpe:2.3:a:commvault:commvault:11.28.72
-
cpe:2.3:a:commvault:commvault:11.28.73
-
cpe:2.3:a:commvault:commvault:11.28.74
-
cpe:2.3:a:commvault:commvault:11.28.75
-
cpe:2.3:a:commvault:commvault:11.28.76
-
cpe:2.3:a:commvault:commvault:11.28.77
-
cpe:2.3:a:commvault:commvault:11.28.78
-
cpe:2.3:a:commvault:commvault:11.28.79
-
cpe:2.3:a:commvault:commvault:11.28.8
-
cpe:2.3:a:commvault:commvault:11.28.80
-
cpe:2.3:a:commvault:commvault:11.28.81
-
cpe:2.3:a:commvault:commvault:11.28.82
-
cpe:2.3:a:commvault:commvault:11.28.83
-
cpe:2.3:a:commvault:commvault:11.28.84
-
cpe:2.3:a:commvault:commvault:11.28.85
-
cpe:2.3:a:commvault:commvault:11.28.9
-
cpe:2.3:a:commvault:commvault:11.28.91
-
cpe:2.3:a:commvault:commvault:11.28.92
-
cpe:2.3:a:commvault:commvault:11.28.93
-
cpe:2.3:a:commvault:commvault:11.28.94
-
cpe:2.3:a:commvault:commvault:11.28.95
-
cpe:2.3:a:commvault:commvault:11.28.96
-
cpe:2.3:a:commvault:commvault:11.32.0
-
cpe:2.3:a:commvault:commvault:11.32.1
-
cpe:2.3:a:commvault:commvault:11.32.12
-
cpe:2.3:a:commvault:commvault:11.32.13
-
cpe:2.3:a:commvault:commvault:11.32.19
-
cpe:2.3:a:commvault:commvault:11.32.2
-
cpe:2.3:a:commvault:commvault:11.32.20
-
cpe:2.3:a:commvault:commvault:11.32.21
-
cpe:2.3:a:commvault:commvault:11.32.22
-
cpe:2.3:a:commvault:commvault:11.32.23
-
cpe:2.3:a:commvault:commvault:11.32.28
-
cpe:2.3:a:commvault:commvault:11.32.29
-
cpe:2.3:a:commvault:commvault:11.32.3
-
cpe:2.3:a:commvault:commvault:11.32.30
-
cpe:2.3:a:commvault:commvault:11.32.31
-
cpe:2.3:a:commvault:commvault:11.32.32
-
cpe:2.3:a:commvault:commvault:11.32.33
-
cpe:2.3:a:commvault:commvault:11.32.34
-
cpe:2.3:a:commvault:commvault:11.32.35
-
cpe:2.3:a:commvault:commvault:11.32.36
-
cpe:2.3:a:commvault:commvault:11.32.37
-
cpe:2.3:a:commvault:commvault:11.32.38
-
cpe:2.3:a:commvault:commvault:11.32.39
-
cpe:2.3:a:commvault:commvault:11.32.4
-
cpe:2.3:a:commvault:commvault:11.32.41
-
cpe:2.3:a:commvault:commvault:11.32.42
-
cpe:2.3:a:commvault:commvault:11.32.43
-
cpe:2.3:a:commvault:commvault:11.32.45
-
cpe:2.3:a:commvault:commvault:11.32.46
-
cpe:2.3:a:commvault:commvault:11.32.47
-
cpe:2.3:a:commvault:commvault:11.32.48
-
cpe:2.3:a:commvault:commvault:11.32.49
-
cpe:2.3:a:commvault:commvault:11.32.5
-
cpe:2.3:a:commvault:commvault:11.32.50
-
cpe:2.3:a:commvault:commvault:11.32.52
-
cpe:2.3:a:commvault:commvault:11.32.54
-
cpe:2.3:a:commvault:commvault:11.32.55
-
cpe:2.3:a:commvault:commvault:11.32.56
-
cpe:2.3:a:commvault:commvault:11.32.57
-
cpe:2.3:a:commvault:commvault:11.32.58
-
cpe:2.3:a:commvault:commvault:11.32.59
-
cpe:2.3:a:commvault:commvault:11.32.6
-
cpe:2.3:a:commvault:commvault:11.32.60
-
cpe:2.3:a:commvault:commvault:11.32.61
-
cpe:2.3:a:commvault:commvault:11.32.62
-
cpe:2.3:a:commvault:commvault:11.32.63
-
cpe:2.3:a:commvault:commvault:11.32.64
-
cpe:2.3:a:commvault:commvault:11.32.65
-
cpe:2.3:a:commvault:commvault:11.32.66
-
cpe:2.3:a:commvault:commvault:11.32.67
-
cpe:2.3:a:commvault:commvault:11.32.69
-
cpe:2.3:a:commvault:commvault:11.32.7
-
cpe:2.3:a:commvault:commvault:11.32.70
-
cpe:2.3:a:commvault:commvault:11.32.71
-
cpe:2.3:a:commvault:commvault:11.32.73
-
cpe:2.3:a:commvault:commvault:11.32.74
-
cpe:2.3:a:commvault:commvault:11.32.76
-
cpe:2.3:a:commvault:commvault:11.32.77
-
cpe:2.3:a:commvault:commvault:11.32.78
-
cpe:2.3:a:commvault:commvault:11.32.79
-
cpe:2.3:a:commvault:commvault:11.32.8
-
cpe:2.3:a:commvault:commvault:11.32.80
-
cpe:2.3:a:commvault:commvault:11.32.81
-
cpe:2.3:a:commvault:commvault:11.32.83
-
cpe:2.3:a:commvault:commvault:11.32.84
-
cpe:2.3:a:commvault:commvault:11.32.85
-
cpe:2.3:a:commvault:commvault:11.32.86
-
cpe:2.3:a:commvault:commvault:11.36.0
-
cpe:2.3:a:commvault:commvault:11.36.1
-
cpe:2.3:a:commvault:commvault:11.36.10
-
cpe:2.3:a:commvault:commvault:11.36.12
-
cpe:2.3:a:commvault:commvault:11.36.14
-
cpe:2.3:a:commvault:commvault:11.36.16
-
cpe:2.3:a:commvault:commvault:11.36.18
-
cpe:2.3:a:commvault:commvault:11.36.20
-
cpe:2.3:a:commvault:commvault:11.36.22
-
cpe:2.3:a:commvault:commvault:11.36.24
-
cpe:2.3:a:commvault:commvault:11.36.25
-
cpe:2.3:a:commvault:commvault:11.36.27
-
cpe:2.3:a:commvault:commvault:11.36.28
-
cpe:2.3:a:commvault:commvault:11.36.29
-
cpe:2.3:a:commvault:commvault:11.36.3
-
cpe:2.3:a:commvault:commvault:11.36.30
-
cpe:2.3:a:commvault:commvault:11.36.32
-
cpe:2.3:a:commvault:commvault:11.36.34
-
cpe:2.3:a:commvault:commvault:11.36.35
-
cpe:2.3:a:commvault:commvault:11.36.36
-
cpe:2.3:a:commvault:commvault:11.36.37
-
cpe:2.3:a:commvault:commvault:11.36.38
-
cpe:2.3:a:commvault:commvault:11.36.39
-
cpe:2.3:a:commvault:commvault:11.36.41
-
cpe:2.3:a:commvault:commvault:11.36.42
-
cpe:2.3:a:commvault:commvault:11.36.43
-
cpe:2.3:a:commvault:commvault:11.36.6
-
cpe:2.3:a:commvault:commvault:11.36.8
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-