Source |
The Hacker News |
Identifiant |
8671939 |
Date de publication |
2025-05-05 21:31:00 (vue: 2025-05-05 18:07:15) |
Titre |
Commvault CVE-2025-34028 ajouté à CISA KEV après l'exploitation active confirmée Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed |
Texte |
L'Agence américaine de sécurité de la cybersécurité et de l'infrastructure (CISA) a ajouté une faille de sécurité de sécurité maximale impactant le Centre de commandement de Commvault à son catalogue connu des vulnérabilités exploités (KEV), un peu plus d'une semaine après sa divulgation publiquement.
La vulnérabilité en question est le CVE-2025-34028 (score CVSS: 10.0), un bug de traversée de chemin qui affecte la version de 11,38
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog, a little over a week after it was publicly disclosed.
The vulnerability in question is CVE-2025-34028 (CVSS score: 10.0), a path traversal bug that affects 11.38 Innovation Release, from versions |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
2025 34028 active added affects after agency bug catalog center cisa command commvault confirmed cve cvss cybersecurity disclosed exploitation exploited flaw from has impacting infrastructure innovation its kev known little maximum over path publicly question release score: security severity traversal versions vulnerabilities vulnerability week |
Tags |
Vulnerability
|
Stories |
|
Move |
|