PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-34028 Commvault CVE debrief

CVE-2025-34028 is a path traversal vulnerability affecting Commvault Command Center that CISA added to the Known Exploited Vulnerabilities catalog on 2025-05-02. Because it is listed in KEV, organizations should treat it as an active-risk issue and prioritize remediation using the vendor’s guidance or CISA’s recommended actions.

Vendor
Commvault
Product
Command Center
CVSS
CRITICAL 9.3
CISA KEV
Listed
Original CVE published
2025-05-02
Original CVE updated
2025-05-02
Advisory published
2025-05-02
Advisory updated
2025-05-02

Who should care

Organizations running Commvault Command Center, especially security and infrastructure teams responsible for patching, configuration, and incident response. Cloud-service users should also review the CISA guidance referenced in the KEV entry.

Technical summary

The supplied corpus identifies the issue as a path traversal vulnerability in Commvault Command Center. CISA’s KEV catalog marks it as known exploited and gives a remediation due date of 2025-05-23. No CVSS score or additional technical detail was provided in the supplied sources.

Defensive priority

Urgent. KEV listing means this vulnerability is already known to be exploited in the wild, so remediation should be prioritized immediately and completed before the 2025-05-23 due date if possible.

Recommended defensive actions

  • Apply mitigations or fixes according to Commvault’s security advisory and vendor instructions.
  • Inventory all Commvault Command Center instances and confirm they are covered by the latest remediation guidance.
  • If mitigations are unavailable, discontinue use of the product until a supported fix or workaround is in place.
  • For cloud services, follow applicable CISA BOD 22-01 guidance referenced by the KEV catalog.
  • Monitor affected environments for unusual access patterns and review logs for signs of compromise.

Evidence notes

This debrief is based only on the supplied KEV metadata and linked official references. The corpus establishes: the CVE identifier, the vulnerability class (path traversal), the product (Commvault Command Center), KEV status, the KEV add date (2025-05-02), and the remediation due date (2025-05-23). No CVSS score was supplied. The KEV notes also reference the Commvault security advisory and the NVD record.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-34028 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-34028

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-34028 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-34028

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.