Latest Commvault vulnerability: CVE-2025-34028 #
Commvault published a security advisory for a critical security vulnerability found in the Command Center installation.
This vulnerability has been assigned CVE-2025-34028 and has been rated highly critical with a CVSS score of 10.0.
What is the impact? #
This vulnerability is only found within the 11.38 Innovation Release (11.38.0 through 11.38.19). A path traversal vulnerability identified in the Command Center installation allows an unauthenticated attacker to upload ZIP files, which could lead to remote code execution.
Are updates available? #
Commvault has issued a 11.38.20 release that patches the vulnerability.
How do I find potentially vulnerable software with runZero? #
Vulnerable services can be found by navigating to the Services Inventory and using the following query:
_service.last.http.uri:="%commandcenter%" AND _service.protocol:http AND _asset.protocol:http About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

