CVE-2025-57791: Argument Injection Vulnerability in CommServe
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57791?
CVE-2025-57791 has been classified with a high severity due to its potential for remote command injection.
How do I fix CVE-2025-57791?
To fix CVE-2025-57791, upgrade Commvault to version 11.36.60 or later, which addresses the vulnerability.
What types of attacks are possible with CVE-2025-57791?
CVE-2025-57791 enables remote attackers to inject or manipulate command-line arguments, which could lead to unauthorized execution of commands.
Which versions of Commvault are affected by CVE-2025-57791?
Commvault versions prior to 11.36.60 are affected by CVE-2025-57791.
Is CVE-2025-57791 an input validation issue?
Yes, CVE-2025-57791 is caused by insufficient input validation in internal components of Commvault.