boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-34028

Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   H   H    9.3   .9760   99.9   YES
AFFECTED
  Product                            Versions   Fixed
  Command Center Innovation Release  11.38.0 –  —
TIMELINE
  Apr 15  Reserved by VulnCheck
  Apr 22  Published (CNA: VulnCheck)
  May 2   Added to CISA KEV, remediation due 2025-05-23
CWE-22, CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · KEV due May 23, 2025

Description

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 15, 2025ReservedReserved by VulnCheck
April 22, 2025PublishedPublished (CNA: VulnCheck)
May 2, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-05-23

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
CommvaultCommand Center Innovation Release—11.38.0—

Weaknesses

CWE-22 · CWE-306

References (5)

Related

Authoritative record: CVE-2025-34028 at cve.org

Vendors: commvault

Weaknesses: CWE-22 · CWE-306

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-34028 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.