Cyber Resilience

CVE-2025-3928

Commvault 11.20.0 – 11.20.217

CISA KEVActive ExploitationEUVD Exploited
Published
25 April 2025
Modified
17 June 2026
KEV Added
28 April 2025
Patch / advisory
CVSS Score v4 8.7
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.021 80th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2025-3928 is a high-severity an unspecified weakness vulnerability in Commvault Commvault. Its CVSS base score is 8.7 (High).

Operationally, ranked in the top 20% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Commvault Web Server contains an unspecified vulnerability that permits remote authenticated attackers to compromise the server by creating and executing webshells. The flaw affects multiple supported versions of the Commvault platform on both Windows and Linux and carries a CVSS 4.0 score of 8.7 reflecting high impact to confidentiality, integrity, and availability.

An attacker who already possesses valid credentials can upload and run arbitrary webshell code on the affected web server, thereby gaining persistent control over the Commvault environment and any data or systems it manages. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 28 April 2025, confirming active exploitation in the wild.

Official Commvault advisories and CISA alerts direct customers to apply the patches released in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217. The EPSS score has remained flat at 0.2863 with no material increase since disclosure.

EU & UK References

Vulnerability Data

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217…

more

for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

CWE(s)
KEV Date Added
28 April 2025

Related Threats

CVEs Like This One

CVE-2025-34028Same product: Commvault Commvaultboth on KEV
CVE-2025-12776Same product: Commvault Commvault
CVE-2021-26828Same product: Linux Linux Kernelboth on KEV
CVE-2022-47986Same product: Linux Linux Kernelboth on KEV
CVE-2021-26829Same product: Linux Linux Kernelboth on KEV
CVE-2015-0310Same product: Linux Linux Kernelboth on KEV
CVE-2014-9163Same product: Linux Linux Kernelboth on KEV
CVE-2020-4006Same product: Linux Linux Kernelboth on KEV
CVE-2022-2856Same product: Linux Linux Kernelboth on KEV
CVE-2014-8439Same product: Linux Linux Kernelboth on KEV

Affected Assets

commvault
commvault
11.20.0 — 11.20.217 · 11.28.0 — 11.28.141 · 11.32.0 — 11.32.89

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References