ZDI-CAN-13889: Commvault CommCell Demo_ExecuteProcessOnGroup Exposed Dangerous Function Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DemoExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-13889?
ZDI-CAN-13889 is a critical vulnerability that allows remote code execution due to a flaw in the authentication mechanism.
How do I fix ZDI-CAN-13889?
To fix ZDI-CAN-13889, update the Commvault CommCell software to the latest version that addresses this vulnerability.
Which versions of Commvault CommCell are affected by ZDI-CAN-13889?
ZDI-CAN-13889 affects specific installations of Commvault CommCell prior to the security update that mitigates the vulnerability.
Can ZDI-CAN-13889 be exploited without authentication?
No, ZDI-CAN-13889 requires authentication, but the authentication can be bypassed, making it particularly dangerous.
What impact does ZDI-CAN-13889 have on systems?
Exploitation of ZDI-CAN-13889 can lead to arbitrary code execution, potentially compromising system integrity and data security.