Commvault: Vulnerability Patch Works as Intended
ID: a391799a-ef95-56d1-82e7-37207feb1a03
STIX ID: report--a391799a-ef95-56d1-82e7-37207feb1a03
Feed Name: Dark Reading
Commvault disclosed a maximum-severity pre-auth SSRF (CVE-2025-34028, CVSS 10.0) in Command Center that can lead to complete compromise of affected environments; fixes were released in 11.38.20 and 11.38.25 with additional updates (SP38-CU20-433 / SP38-CU20-436 and SP38-CU25-434 / SP38-CU25-438). A researcher reported that a proof-of-concept still worked against updated systems, but Commvault said the researcher tested unregistered/trial instances that had not received the manual additional updates; Commvault reports no signs of active exploitation and has broadened patch availability to trial users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
