CVE-2025-3928
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Summary dbcve.org
Commvault Web Server contains a vulnerability allowing remote, authenticated attackers to create and execute webshells on the affected system. This enables arbitrary code execution with the privileges of the web server process, leading to potential complete system compromise. The CVSS 8.8 indicates network-based exploitation with high confidentiality and availability impact.
Mitigation
Upgrade Commvault to version 11.36.46, 11.32.89, 11.28.141, or 11.20.217 (or later) for both Windows and Linux platforms. Since this vulnerability is actively exploited (CISA KEV), prioritize patching immediately and audit for indicators of compromise.