CVE-2025-3928
KEV
🔴 Łataj teraz
Nieokreślona podatność w serwerze Commvault umożliwia zdalne przejęcie kontroli przez uwierzytelnionego atakującego.
CVSS
8.8
EPSS
2.3%
Exploit
weaponized
Vendor
commvault
Opis źródłowy (NVD)
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.3% |
| Opublikowano (NVD) | 2025-04-25 16:15:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 18:17:13 UTC |
Referencje
- https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html (9119a7d8-5eab-497f-8521-727c672e3725) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928 (9119a7d8-5eab-497f-8521-727c672e3725) [Third Party Advisory, US Government Resource]
- https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic (9119a7d8-5eab-497f-8521-727c672e3725) [Third Party Advisory, US Government Resource]
- https://www.commvault.com/blogs/customer-security-update (9119a7d8-5eab-497f-8521-727c672e3725) [Vendor Advisory]
- https://www.commvault.com/blogs/notice-security-advisory-update (9119a7d8-5eab-497f-8521-727c672e3725) [Vendor Advisory]
- https://www.commvault.com/blogs/security-advisory-march-7-2025 (9119a7d8-5eab-497f-8521-727c672e3725) [Vendor Advisory]
- https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data/ (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]