CVE-2017-3195
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cret@cert.org — http://kb.commvault.com/article/SEC0013
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| commvault | edge | 11.0.0 | |
References
- http://kb.commvault.com/article/SEC0013
- http://redr2e.com/commvault-edge-cve-2017-3195/
- http://www.securityfocus.com/bid/96941
- https://www.exploit-db.com/exploits/41823/
- https://www.kb.cert.org/vuls/id/214283
- http://kb.commvault.com/article/SEC0013
- http://redr2e.com/commvault-edge-cve-2017-3195/
- http://www.securityfocus.com/bid/96941
- https://www.exploit-db.com/exploits/41823/
- https://www.kb.cert.org/vuls/id/214283
CWEs
CWE-121 CWE-119
Verify integrity in audit chain (admin only). AS-IS.