← Back to CVE List
Vulnerability Intelligence Report

CVE-2017-3195

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:21.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-121 ↗CWE-121: Stack-based Buffer Overflow

Affected Products & Versions

Vendor Product Affected Versions
Commvault Service Pack 6 Version 11 prior to SP7 (affected), version 11 SP6 prior to hotfix 590 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
21.387%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2016-12-05T00:00:00
Published2017-12-15T14:00:00
Patch Date2017-03-16
Last Updated2024-08-05T14:16:28

LINK COPIED TO CLIPBOARD