CyberSecurity news

FlagThis

@arcticwolf.com //
Commvault has issued updated advisories regarding a critical vulnerability, CVE-2025-34028, affecting Commvault Command Center. The flaw allows for remote code execution, posing a significant risk to organizations utilizing the platform. Initial patches were released, but Commvault has since clarified that simply being on versions 11.38.20 or 11.38.25 is not enough to fully remediate the vulnerability. Specific updates within those versions are required to effectively address the security gap, an update which was clarified on May 7, 2025.

The Cybersecurity and Infrastructure Security Agency (CISA) has added the Commvault Command Center vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This designation underscores the severity of the flaw and the potential for active exploitation, prompting immediate action from organizations to apply the necessary updates. Fortunately, Commvault seems to have resolved the issue where the "Upgrade software" option was not working for unregistered systems. It is now possible to obtain the necessary fixes for CVE-2025-34028 by clicking "Upgrade now," even without being registered with Commvault.

However, the "Check updates" button in the "Download or copy software" section is still malfunctioning. It incorrectly reports systems as "Up-to-date" even when they are not fully patched against CVE-2025-34028. Users must ensure they have the appropriate specific updates within versions 11.38.20 or 11.38.25 as mentioned in Commvault's clarified advisory to achieve full remediation. Staying vigilant, monitoring security advisories, and diligently applying patches and updates are crucial for maintaining a robust security posture and mitigating potential cyber threats.
Original img attribution: https://arcticwolf.com/wp-content/uploads/2022/07/aw-security-bulletin-UF-Featured-Image_dots_04-220306.jpg
ImgSrc: arcticwolf.com

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • Arctic Wolf: Follow-Up: Commvault Updates Advisory With Fixed Versions for Critical Commvault Command Center Vulnerability (CVE-2025-34028)
  • malware.news: News about Commvault updates addressing a critical vulnerability.
Classification:
  • HashTags: #Commvault #CVE202534028 #Vulnerability
  • Company: Commvault
  • Target: Commvault Command Center users
  • Product: Commvault Command Center
  • Feature: command center
  • Type: Vulnerability
  • Severity: Critical