Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 23, 2025

CVE-2025-34028

High
EPSS 51.1%CISA KEV
Commvault/Command Center

Description

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

EPSS — Exploit Probability

51.1%

Higher than 97.8% of all CVEs

Required Action

https://documentation.commvault.com/securityadvisories/CV_2025_04_1.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-34028

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
51.1%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 2, 2025

Added to KEV

May 2, 2025

Remediation Due

May 23, 2025

Affected Product

Commvault

Command Center

View all Commvault CVEs