The vulnerability, tracked as CVE-2025-34028, could allow attackers to compromise enterprise backup systems without requiring authentication, potentially putting organizations’ most critical data at risk. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The vulnerability is particularly concerning given the critical role backup solutions play in organizations’ cybersecurity strategies, especially against ransomware threats. Risk FactorsDetailsAffected ProductsCommvault Command Center Innovation Release, versions 11.38.0 through 11.38.19ImpactPre-authenticated Remote Code Execution (RCE)Exploit PrerequisitesNo authentication required. Security teams should also review their Commvault deployments for signs of compromise, as the now-public exploit code could lead to increased exploitation attempts. “Backup and Replication solutions have become prime targets for ransomware operators for logical reasons,” the researchers explained. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. This request triggers a Server-Side Request Forgery (SSRF) vulnerability where the application fetches content from an attacker-controlled server. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 24 Apr 2025 12:05:08 +0000