Remote Code Execution Vulnerability in Commvault CommCell by Commvault
CVE-2021-34996
What is CVE-2021-34996?
A vulnerability exists in Commvault CommCell 11.22.22 that permits remote attackers to execute arbitrary code. While authentication is needed to exploit this flaw, the current authentication method can be circumvented. The issue resides within the Demo_ExecuteProcessOnGroup workflow, where an attacker can craft a malicious workflow, allowing them to execute any command with SYSTEM privileges. This vulnerability poses a significant risk as it potentially enables unauthorized access and execution of harmful code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CommCell 11.22.22
References
EPSS Score
20% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
