ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-34028CVE-2025-3928

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-34028
Unauthenticated Path Traversal RCE in Commvault Command Center

Commvault Command Center (Innovation Release 11.38.0 through 11.38.20) is vulnerable to a path traversal flaw (CWE-22) that requires no authentication (CWE-306). An unauthenticated remote attacker uploads a maliciously crafted ZIP file masquerading as an install package to the Command Center web interface; when the target server expands the archive, path traversal lets attacker-controlled files, including malicious JSP webshells, be written outside the intended location. The result is unauthenticated remote code execution on the backup management server, giving attackers a foothold in a core enterprise data-protection component. Any organization running the affected 11.38 release train of Command Center is exposed, particularly if the console is reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-02, carries a 97.7% EPSS exploitation probability, and public PoC exploit code is available.

Do: Upgrade Command Center to 11.38.20 with hotfixes SP38-CU20-433 and SP38-CU20-436, or to 11.38.25 with SP38-CU25-434 and SP38-CU25-438. Until patched, restrict internet exposure of the Command Center web console and check for signs of compromise such as unexpected JSP files or webshells written by the application. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use of the product.

9.398% KEV PoC
  • Commvault Command Center (Innovation Release) 11.38.0 to 11.38.20; fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436, and in 11.38.25 with SP38-CU25-434 and SP38-CU25-438
largelikely tens of thousands of enterprise deployments running the affected 11.38 release train, of which roughly hundreds to a few thousand Command Center…
CVE-2025-3928
Actively Exploited Authenticated Webshell Flaw in Commvault Web Server

CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent.

Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

8.72% KEV
  • Commvault Web Server Commvault Web Server on Windows and Linux, versions prior to the fixes in each supported release stream: 11.36 before 11.36.46, 11.32 before 11.32.89, 11.28 bef
large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands
Full article514 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 05, 2025Vulnerability / Zero-Day

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog, a little over a week after it was publicly disclosed.

The vulnerability in question is CVE-2025-34028 (CVSS score: 10.0), a path traversal bug that affects 11.38 Innovation Release, from versions 11.38.0 through 11.38.19. It has been addressed in versions 11.38.20 and 11.38.25.

"Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code," CISA said.

The flaw essentially permits an attacker to upload ZIP files that, when decompressed on the target server, could result in remote code execution.

Cybersecurity company watchTowr Labs, which was credited with discovering and reporting the bug, said the problem resides in an endpoint called "deployWebpackage.do" that triggers a pre-authenticated Server-Side Request Forgery (SSRF), ultimately resulting in code execution when using a ZIP archive file containing a malicious .JSP file.

It's currently not known in what context the vulnerability is being exploited, but the development makes it the second Commvault flaw to be weaponized in real-world attacks after CVE-2025-3928 (CVSS score: 8.7), an unspecified issue in the Commvault Web Server that allows a remote, authenticated attacker to create and execute web shells.

The company revealed last week that the exploitation activity affected a small number of customers but noted that there has been no unauthorized access to customer backup data.

In light of active exploitation of CVE-2025-34028, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary patches by May 23, 2025, to secure their networks.

Update

Commvault, in an update to its advisory on May 6, 2025, said the vulnerability can be remediated by installing versions 11.38.20 or 11.38.25 alongside supplemental updates -

  • 11.38.20, with the additional updates: SP38-CU20-433 and SP38-CU20-436
  • 11.38.25, with the additional updates: SP38-CU25-434 and SP38-CU25-438

Security researcher Will Dormann, who found that deploying just 11.38.20 or 11.38.25 does not fix the flaw, said "I cannot think of a behavior that is more vindictive to their customers to botch language in an advisory so bad, and also to not bother bumping release versions for the fixes for a CVSS 10 EITW vulnerability."

In a follow-up post on Mastodon, Dormann explained the issue further: "The 11.38 version of Commvault is what's referred to as the 'Innovation Release' of the software, where the expectation is that 'Pioneer customers' register with Commvault and are specifically approved to even see updates that are available."

"The problem with this: Customers who fire up a Commvault 11.38 VM through Azure or the like did not [go] through the front door of registering with Commvault. As such, they would NOT SEE UPDATES AVAILABLE. This was ... not ideal."

The security researcher also noted that Commvault changed the backend to provide the "Additional updates" that fix CVE-2025-34028 for those who use Azure or AWS via a manual download process.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html