Highest-Risk Security Flaw Found in Commvault Backup Solutions
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34028 | Unauthenticated Path Traversal RCE in Commvault Command Center Commvault Command Center (Innovation Release 11.38.0 through 11.38.20) is vulnerable to a path traversal flaw (CWE-22) that requires no authentication (CWE-306). An unauthenticated remote attacker uploads a maliciously crafted ZIP file masquerading as an install package to the Command Center web interface; when the target server expands the archive, path traversal lets attacker-controlled files, including malicious JSP webshells, be written outside the intended location. The result is unauthenticated remote code execution on the backup management server, giving attackers a foothold in a core enterprise data-protection component. Any organization running the affected 11.38 release train of Command Center is exposed, particularly if the console is reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-02, carries a 97.7% EPSS exploitation probability, and public PoC exploit code is available. Do: Upgrade Command Center to 11.38.20 with hotfixes SP38-CU20-433 and SP38-CU20-436, or to 11.38.25 with SP38-CU25-434 and SP38-CU25-438. Until patched, restrict internet exposure of the Command Center web console and check for signs of compromise such as unexpected JSP files or webshells written by the application. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use of the product. | 9.3 | 98% | KEV PoC |
| largelikely tens of thousands of enterprise deployments running the affected 11.38 release train, of which roughly hundreds to a few thousand Command Center… |
Full article310 words · extracted from infosecurity-magazine.com · click to collapse
A new critical vulnerability has been found in Commvault, illustrating that backup and replication solutions are highly sought after by cyber threat actors due to their crucial role in data management.
On April 24, watchTowr published a report on a newly-discovered path traversal vulnerability in Commvault Command Center Innovation Release version 11.38 on Linux and Windows.
Commvault Command Center Innovation Release is a web-based management interface that provides a centralized platform for managing Commvault data protection and management operations.
When exploited, this flaw allows an unauthenticated actor to upload ZIP files and perform remote code execution (RCE), thus leading to a complete compromise of the Command Center environment.
The vulnerability was identified as CVE-2025-34028 and given the highest severity score, 10.0 (CVSS v3.1).
Commvault has released a fix for Commvault Command Center Innovation Release versions 11.38.20 and above.
Customers have been urged to apply the new versions as soon as possible. Commvault said that if installing the update is not feasible, customers should isolate the Command Center installation from external network access.
CVE-2025-34028 Disclosure Timeline
This vulnerability is due to improper limitation of a pathname to a restricted directory (also known as a path traversal flaw) in Commvault Command Center Innovation Release version 11.38.
It was discovered by watchTowr on April 7, which immediately contacted Commvault.
Commvault released a fix on April 10th and published a security advisory on April 17.
Upon watchTowr request, vulnerability intelligence firm VulnCheck, a CVE Numbering Authority (CNA), assigned the CVE-2025-34028 identifier to the vulnerability.
In its latest report, watchTowr shared a proof-of-concept (PoC) exploit for CVE-2025-34028.
Backup and replication solutions have been massively targeted lately for vulnerability exploits, as seen in recent attacks on solutions like Veeam and NAKIVO, highlighting the growing trend of threat actors focusing on these critical data management systems to gain unauthorized access and control.
Photo credits: T. Schneider/Shutterstock
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/critical-vulnerability-commvault/