PatchSiren cyber security CVE debrief
CVE-2025-34028 Commvault CVE debrief
CVE-2025-34028 is a path traversal vulnerability affecting Commvault Command Center that CISA added to the Known Exploited Vulnerabilities catalog on 2025-05-02. Because it is listed in KEV, organizations should treat it as an active-risk issue and prioritize remediation using the vendor’s guidance or CISA’s recommended actions.
- Vendor
- Commvault
- Product
- Command Center
- CVSS
- CRITICAL 9.3
- CISA KEV
- Listed
- Original CVE published
- 2025-05-02
- Original CVE updated
- 2025-05-02
- Advisory published
- 2025-05-02
- Advisory updated
- 2025-05-02
Who should care
Organizations running Commvault Command Center, especially security and infrastructure teams responsible for patching, configuration, and incident response. Cloud-service users should also review the CISA guidance referenced in the KEV entry.
Technical summary
The supplied corpus identifies the issue as a path traversal vulnerability in Commvault Command Center. CISA’s KEV catalog marks it as known exploited and gives a remediation due date of 2025-05-23. No CVSS score or additional technical detail was provided in the supplied sources.
Defensive priority
Urgent. KEV listing means this vulnerability is already known to be exploited in the wild, so remediation should be prioritized immediately and completed before the 2025-05-23 due date if possible.
Recommended defensive actions
- Apply mitigations or fixes according to Commvault’s security advisory and vendor instructions.
- Inventory all Commvault Command Center instances and confirm they are covered by the latest remediation guidance.
- If mitigations are unavailable, discontinue use of the product until a supported fix or workaround is in place.
- For cloud services, follow applicable CISA BOD 22-01 guidance referenced by the KEV catalog.
- Monitor affected environments for unusual access patterns and review logs for signs of compromise.
Evidence notes
This debrief is based only on the supplied KEV metadata and linked official references. The corpus establishes: the CVE identifier, the vulnerability class (path traversal), the product (Commvault Command Center), KEV status, the KEV add date (2025-05-02), and the remediation due date (2025-05-23). No CVSS score was supplied. The KEV notes also reference the Commvault security advisory and the NVD record.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-34028 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-34028
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-34028 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-34028
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.