CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-34028

CVSS 9.3v4.0pub. 2025-04-22upd. 2025-11-06

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

🤖 AI Analysis
How it works

An attacker without any authentication (CWE-306) uploads a crafted ZIP archive impersonating an installation package. During extraction, the server does not properly validate the paths contained in the archive (CWE-22 – path traversal), allowing a JSP file to be written to any location accessible to the application server. The malicious JSP file placed this way is then executed by the server, resulting in full Remote Code Execution in the context of the server process.

Impact

An attacker gains the ability to execute arbitrary code on the server without any authentication, which in practice means complete takeover of the system, including the ability to compromise the integrity and availability of data managed by Commvault.

Mitigation & patch

Commvault Command Center should be updated to a version containing one of the following patches: SP38-CU20-433 or SP38-CU20-436 (for the 11.38.20 line) or SP38-CU25-434 or SP38-CU25-438 (for the 11.38.25 line). Detailed instructions are available in the vendor's official security bulletin at the address indicated in the references (CV_2025_04_1).

Who is affected

Commvault Command Center Innovation Release in versions from 11.38.0 to 11.38.20 and 11.38.25 (before applying appropriate patches); products running on Microsoft Windows and Linux.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Commvault

    APP
    Commvault
    11.38.0 – 11.38.20 (excl.)
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions

CISA KEV — detailsi

Vendori
Commvault
Producti
Command Center
Added to KEVi
May 2, 2025
Remediation deadline (US Federal)i
May 23, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 23 maja 2025
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex