Remote Code Execution Vulnerability in Commvault CommCell by Commvault
CVE-2021-34996

8.8HIGH

Key Information:

Vendor

Commvault

Status
Vendor
CVE Published:
13 January 2022

What is CVE-2021-34996?

A vulnerability exists in Commvault CommCell 11.22.22 that permits remote attackers to execute arbitrary code. While authentication is needed to exploit this flaw, the current authentication method can be circumvented. The issue resides within the Demo_ExecuteProcessOnGroup workflow, where an attacker can craft a malicious workflow, allowing them to execute any command with SYSTEM privileges. This vulnerability poses a significant risk as it potentially enables unauthorized access and execution of harmful code.

Affected Version(s)

CommCell 11.22.22

References

EPSS Score

23% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brandon Perry, Justin Kennedy and Steven Seeley of Source Incite
.