ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028)

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-34028

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-34028
Unauthenticated Path Traversal RCE in Commvault Command Center

Commvault Command Center (Innovation Release 11.38.0 through 11.38.20) is vulnerable to a path traversal flaw (CWE-22) that requires no authentication (CWE-306). An unauthenticated remote attacker uploads a maliciously crafted ZIP file masquerading as an install package to the Command Center web interface; when the target server expands the archive, path traversal lets attacker-controlled files, including malicious JSP webshells, be written outside the intended location. The result is unauthenticated remote code execution on the backup management server, giving attackers a foothold in a core enterprise data-protection component. Any organization running the affected 11.38 release train of Command Center is exposed, particularly if the console is reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-02, carries a 97.7% EPSS exploitation probability, and public PoC exploit code is available.

Do: Upgrade Command Center to 11.38.20 with hotfixes SP38-CU20-433 and SP38-CU20-436, or to 11.38.25 with SP38-CU25-434 and SP38-CU25-438. Until patched, restrict internet exposure of the Command Center web console and check for signs of compromise such as unexpected JSP files or webshells written by the application. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use of the product.

9.398% KEV PoC
  • Commvault Command Center (Innovation Release) 11.38.0 to 11.38.20; fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436, and in 11.38.25 with SP38-CU25-434 and SP38-CU25-438
largelikely tens of thousands of enterprise deployments running the affected 11.38 release train, of which roughly hundreds to a few thousand Command Center…
Full article276 words · extracted from helpnetsecurity.com · click to collapse

If your organization is using Commvault Command Center for your data protection, backup creation, configuration and restoration needs, you should check whether your on-premise installation has been upgraded to patch a critical vulnerability (CVE-2025-34028) that could allow unauthenticated remote code execution.

Commvault CVE-2025-34028

About CVE-2025-34028

CVE-2025-34028 is a path traversal vulnerability affecting Commvault Command Center (Innovation Release) versions from 11.38.0 to 11.38.19, on Windows and Linux.

It was unearthed by watchTowr researcher Sonny Macdonald, who discovered an endpoint that can be reached without prior authentication, and a server-side request forgery (SSRF) vulnerability and path traversal issues that can be exploited to:

  • Force the vulnerable Commvault instances to fetch a malicious ZIP file from an externally controlled server
  • Unzip the file, execute and trigger the shell within it, thus achieving remote code execution

Macdonald has explained the whole process in a blog post published on Thursday, and released a proof-of-concept (PoC) exploit that can be used to check whether a Commvault Command Center instance is vulnerable.

What to do?

According to Commvault, CVE-2025-34028 does not impact the Long-Term Support Commvault Platform Releases, but just the 11.38 Innovation Release. It has been fixed earlier this month in versions 11.38.20 and 11.38.25.

“Innovation releases are automatically managed according to predefined schedules, so manual intervention is not required,” the company said in the accompanying security advisory.

“If installing the update is not feasible, then isolate the Command Center installation from external network access.”

UPDATE (May 5, 2025, 03:45 a.m. ET):

CVE-2025-34028 has been added to CISA’s Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/24/critical-commvault-rce-vulnerability-fixed-poc-available-cve-2025-34028/